Incident tracker · 19 Jul 2025

Are you exposed to the eslint-config-prettier supply-chain (2025)?

Maintainer's npm token was phished; malicious versions executed an install.js that dropped a node-gyp.dll malware payload on Windows installs.

Confirmed-compromised packages1 package
npm
eslint-config-prettiercompromised: 8.10.1, 9.1.1, 10.1.6, 10.1.7
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo