Package has malware in it
https://osv.dev/vulnerability/MAL-2025-6022
{
"modified": "2025-07-21T06:24:05Z",
"published": "2025-07-21T06:24:05Z",
"schema_version": "1.5.0",
"id": "MAL-2025-6022",
"summary": "Malicious code in eslint-config-prettier (npm)",
"details": "This package installs a windows based malware file node-gyp.dll via install.js",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "eslint-config-prettier"
},
"versions": [
"8.10.1",
"9.1.1",
"10.1.6",
"10.1.7"
]
}
],
"references": [
{
"type": "WEB",
"url": "https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/"
}
],
"credits": [
{
"name": "GitHax - Software Supply Chain Threat Intelligence",
"type": "FINDER",
"contact": [
"https://githax.com"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
0 条评论