Bug 2382071 (CVE-2025-54313)

Summary: CVE-2025-54313 eslint-config-prettier: Eslint-config-prettier Supply Chain Compromise
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, adkhan, adudiak, anjoseph, anpicker, asoldano, bbaranow, bmaxwell, bparees, brian.stansberry, caswilli, cdewolf, chfoley, darran.lofthouse, dhanak, dkreling, dosoudil, drosa, dsimansk, fjuma, gotiwari, gryan, gzaronik, hasun, ibek, istudens, ivassile, iweiss, jchui, jfula, jhe, jhorak, jhuff, jkoehler, jowilson, jprabhak, jrokos, kaycoth, kingland, kshier, ktsao, kverlaen, lball, lchilton, lgao, lphiri, matzew, mnovotny, mosmerov, msochure, msvehla, mvyas, mwringe, nboldt, ngough, nwallace, nyancey, omaciel, ometelka, pesilva, pjindal, pmackay, psrna, ptisnovs, rstancel, sausingh, sdawley, sfeifer, smaestri, stcannon, swoodman, syedriko, tom.jenkinson, tpopela, veshanka, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in eslint-config-prettier. An affected version contains embedded malicious code that executes an `install.js` file during package installation. This script launches the `node-gyp.dll` malware on Windows systems, allowing a remote attacker to execute arbitrary code.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2025-07-19 17:01:10 UTC
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.