CI/CD Compromise 2025 Incident #51 CVE-2025-54313

eslint-config-prettier

Estimated Financial Impact
14K+ direct dependents
Blast Radius
Phishing; Dependabot auto-merged malicious updates

What Happened

A phishing attack pushed poisoned versions of eslint-config-prettier directly to npm without corresponding source code changes. More than 14,000 packages declared it as a direct dependency. Dependabot auto-merged the malicious updates into consuming repositories, amplifying the blast radius.

✓

Risk Guard: Caught

SOURCE_MALFORMED_METADATA detects poisoned versions without source changes; PACKAGE_ACTIVE_MALWARE

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARESOURCE_MALFORMED_METADATA

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught SOURCE_MALFORMED_METADATA detects poisoned versions without source changes; PACKAGE_ACTIVE_MALWARE
Sonatype (Nexus) Partial Firewall may block after flagged
Socket Caught Behavioral analysis detects malicious payload in new version
Snyk Missed No malware detection
Black Duck Missed No malware detection
Endor Labs Missed No malware detection
← GhostAction campaign Polyfill.io domain takeover →