Prettier NPM Packages Compromised in Supply Chain Attack

29 feross 4 7/19/2025, 5:30:18 PM socket.dev ↗

Comments (4)

acheong08 · 2h ago
Anyone done reverse engineering on what the dll does? The advice of rolling back versions wouldn't be sufficient if it also exfiltrated ssh keys and such for pushing to git
c-hendricks · 2h ago
eslint-config-prettier and eslint-plugin-prettier, not prettier proper.

https://news.ycombinator.com/item?id=44609732

gausswho · 3h ago
Only vulnerable on Windows machines?
tiagod · 4h ago
This is pretty bad.