# Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware

DevFeed: [Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware](<https://devfeed.tech/articles/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware-8008.md>)

Original publisher: [Read original article](<https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/>)

Author: Liran Tal

Published: 2025-07-22T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [eslint](<https://devfeed.tech/tags/eslint.md>), [go](<https://devfeed.tech/tags/go.md>), [incident](<https://devfeed.tech/tags/incident.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [malware](<https://devfeed.tech/tags/malware.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [password-reset](<https://devfeed.tech/tags/password-reset.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scm](<https://devfeed.tech/tags/scm.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

An npm supply-chain malware incident used a typosquatted registry domain and phishing emails to steal maintainer credentials and publish malicious package versions.

## Source excerpt

Urgent warning: Maintainers of popular npm packages like ESLint Prettier Plugin were attacked via an npm supply chain malware incident. Learn about the typosquatting, phishing, and impacted packages, plus essential steps to protect your projects.