eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
| Software | From | Fixed in |
|---|---|---|
eslint-config-prettier
|
8.10.1 | 8.10.1.x |
eslint-config-prettier
|
8.10.1 | 8.10.2 |
eslint-config-prettier
|
9.1.1 | 9.1.1.x |
eslint-config-prettier
|
9.1.1 | 9.1.2 |
eslint-config-prettier
|
10.1.6 | 10.1.8 |
eslint-plugin-prettier
|
4.2.2 | 4.2.4 |
synckit
|
0.11.9 | 0.11.9.x |
synckit
|
0.11.9 | 0.11.10 |
@pkgr / core
|
0.2.8 | 0.2.8.x |
@pkgr / core
|
0.2.8 | 0.2.9 |
napi-postinstall
|
0.3.1 | 0.3.1.x |
napi-postinstall
|
0.3.1 | 0.3.2 |
got-fetch
|
5.1.11 | 6.0.0 |
| prettier / eslint-config-prettier | 8.10.1 | 8.10.1.x |
| prettier / eslint-config-prettier | 9.1.1 | 9.1.1.x |
| prettier / eslint-config-prettier | 10.1.6 | 10.1.6.x |
| prettier / eslint-config-prettier | 10.1.7 | 10.1.7.x |
| prettier / eslint-plugin-prettier | 4.2.2 | 4.2.2.x |
| prettier / eslint-plugin-prettier | 4.2.3 | 4.2.3.x |
| un-ts / synckit | 0.11.9 | 0.11.9.x |
| un-ts / pkgr/core | 0.2.8 | 0.2.8.x |
| alexghr / got-fetch | 5.1.1 | 5.1.1.x |
| alexghr / got-fetch | 5.1.2 | 5.1.2.x |
| un-ts / napi-postinstall | 0.3.1 | 0.3.1.x |
| homarr / homarr | 1.29.0 | 1.30.0 |