A phishing attack pushed poisoned versions of eslint-config-prettier directly to npm without corresponding source code changes. More than 14,000 packages declared it as a direct dependency. Dependabot auto-merged the malicious updates into consuming repositories, amplifying the blast radius.
SOURCE_MALFORMED_METADATA detects poisoned versions without source changes; PACKAGE_ACTIVE_MALWARE
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | SOURCE_MALFORMED_METADATA detects poisoned versions without source changes; PACKAGE_ACTIVE_MALWARE |
| Sonatype (Nexus) | Partial | Firewall may block after flagged |
| Socket | Caught | Behavioral analysis detects malicious payload in new version |
| Snyk | Missed | No malware detection |
| Black Duck | Missed | No malware detection |
| Endor Labs | Missed | No malware detection |