# CVE-2025-54313: Prettier Config Package Hijacked

DevFeed: [CVE-2025-54313: Prettier Config Package Hijacked](<https://devfeed.tech/articles/cve-2025-54313-prettier-config-package-hijacked-15.md>)

Original publisher: [Read original article](<https://blog.abhimanyu-saharan.com/posts/cve-2025-54313-prettier-config-package-hijacked>)

Author: Abhimanyu Saharan

Published: 2025-07-29T00:00:00Z

Content type: article

Language: en

Sources: [Abhimanyu Saharan](<https://devfeed.tech/sources/abhimanyu-s-blog.md>)

Topics: [Prettier](<https://devfeed.tech/topics/prettier.md>), [ESLint](<https://devfeed.tech/topics/eslint.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

## AI overview

This article describes CVE-2025-54313, a high-severity supply chain attack involving the hijacking of the eslint-config-prettier package through a phishing compromise.

## Source excerpt

A high-severity CVE exposed eslint-config-prettier to a supply chain attack via a phishing compromise. Learn what happened, who's affected, and how to fix it.