eslint-config-prettier Compromise

discovered 2025-07-21

July 2025 maintainer-phishing compromise that pushed malware through eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core and napi-postinstall, packages with tens of millions of weekly downloads.

Objective

Distribute Windows malware through trusted, high-download npm packages.

Packages

Indicators

Techniques

Read the full analysis →