eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
- Severity:
- High
Description
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
Recommendation
Update the got-fetch package to the latest compatible version. Followings are version details:
- Affected version(s): >= 5.1.11, <= 5.1.12
- Patched version(s): 6.0.0
References
- GHSA-f29h-pxvx-f335
- news.ycombinator.com
- socket.dev
- www.bleepingcomputer.com
- www.npmjs.com
- www.stepsecurity.io
- www.endorlabs.com
- secure.software
- checkmarx.com
- www.cisa.gov
- CVE-2025-54313
- CWE-506
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Elysia affected by arbitrary code injection through cookie config - CVE-2025-66457
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/webpack-builder - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builder - CVE-2025-24360
You might also like:
- Tags:
- npm
- got-fetch
Anything's wrong? Let us know Last updated on January 22, 2026


