<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/supply-chain-attack-targeting-eslint-prettier-plugin-maintainers-oifyodvta" -->

---
title: Supply Chain Attack Targeting ESLint Prettier Plugin...
description: Recent supply chain attacks compromised popular npm packages including eslint-config-prettier and eslint-plugin-prettier through sophisticated phishing...
canonical: https://daily.dev/posts/supply-chain-attack-targeting-eslint-prettier-plugin-maintainers-oifyodvta
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Supply Chain Attack Targeting ESLint Prettier Plugin Maintainers | daily.dev
og:description: Recent supply chain attacks compromised popular npm packages including eslint-config-prettier and eslint-plugin-prettier through sophisticated phishing...
og:url: https://daily.dev/posts/supply-chain-attack-targeting-eslint-prettier-plugin-maintainers-oifyodvta
og:image: https://api.daily.dev/og/posts/OiFyODVta.png
og:image:alt: Supply Chain Attack Targeting ESLint Prettier Plugin Maintainers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Supply Chain Attack Targeting ESLint Prettier Plugin Maintainers

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 2 upvotes · 0 comments

## Summary

Recent supply chain attacks compromised popular npm packages including eslint-config-prettier and eslint-plugin-prettier through sophisticated phishing campaigns using typosquatted domains. Attackers harvested maintainer credentials to inject malware variants, including a Windows DLL called 'Scavenger' for data theft and cross-platform JavaScript loaders for remote control. The attacks affected millions of weekly downloads and thousands of projects, prompting swift responses from maintainers and highlighting the urgent need for enhanced security measures in open source package repositories.

## Content

The recent wave of supply chain attacks targeting npm package repositories underscores critical security vulnerabilities in the open source ecosystem. Prominent npm packages such as `eslint-config-prettier`, `eslint-plugin-prettier`, and the utility package `is` have been compromised through sophisticated phishing campaigns.

Attackers employed typosquatted domains to deceive maintainers into revealing their npm credentials, subsequently injecting malware into widely-used packages. These attacks involved dual malware variants, one being a Windows-specific DLL, dubbed 'Scavenger', which harvested browser data, and the other a cross-platform JavaScript loader granting remote command and control capabilities.

In separate incidents, Toptal's GitHub account was compromised, leading to the distribution of malware through their npm developer toolbox packages, affecting around 5,000 downloads before rectification. This malware was designed to exfiltrate GitHub authentication tokens and persistently establish backdoor access.

The infected packages, with millions of weekly downloads, demonstrated the cascading impact such compromises can have across thousands of projects. Responding swiftly, maintainers have reset credentials, deprecated harmful package versions, and worked with the npm registry to remove infected packages.

These incidents not only spotlight the vulnerability of developer account security but also the expansive reach malware can achieve through trusted repositories and automated publishing workflows. They highlight the pressing need for enhanced security measures, such as Google's OSS rebuild initiative and automated tools like JFrog Curation, to detect and block malicious packages before infiltration into development environments.

As the landscape of open source software continues to grow, it becomes increasingly imperative to fortify package supply chains against cybercriminal strategies aimed at weaponizing maintainer accounts to spread malicious code.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#javascript](https://daily.dev/tags/javascript), [#cyber](https://daily.dev/tags/cyber), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/supply-chain-attack-targeting-eslint-prettier-plugin-maintainers-oifyodvta)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Supply Chain Attack Targeting ESLint Prettier Plugin Maintainers","url":"https://daily.dev/posts/supply-chain-attack-targeting-eslint-prettier-plugin-maintainers-oifyodvta","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/supply-chain-attack-targeting-eslint-prettier-plugin-maintainers-oifyodvta"},"datePublished":"2025-07-22T12:38:52.260Z","dateModified":"2025-07-25T17:40:23.024Z","description":"Recent supply chain attacks compromised popular npm packages including eslint-config-prettier and eslint-plugin-prettier through sophisticated phishing...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6ffdc08e924eaba083876a1e5d7b89fd?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6ffdc08e924eaba083876a1e5d7b89fd?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/supply-chain-attack-targeting-eslint-prettier-plugin-maintainers-oifyodvta","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,javascript,cyber,npm","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Supply Chain Attack Targeting ESLint Prettier Plugin Maintainers"}]}
```

