top of page
perceptive_background_267k.jpg

Supply Chain Security Alert: eslint-config-prettier Package Shows Signs of Compromise

Published:

5 december 2025 om 11:50:29

Alert date:

5 december 2025 om 12:01:17

Source:

stepsecurity.io

Click to open the original link from this advisory

StepSecurity is investigating a potential supply chain security incident involving the eslint-config-prettier npm package. The widely-used package, which helps developers maintain consistent code formatting by turning off ESLint rules that conflict with Prettier, appears to have had multiple versions published with suspicious modifications. This represents a significant supply chain risk given the package's widespread adoption in JavaScript development environments. The compromise could potentially affect numerous downstream projects that depend on this popular configuration package.

Technical details

Mitigation steps:

Affected products:

eslint-config-prettier
npm

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page