<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Prettier</title><description>Actively exploited vulnerabilities affecting Prettier products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/prettier.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-54313 — Prettier eslint-config-prettier Embedded Malicious Code Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-54313</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-54313</guid><description>A malicious version of the popular eslint-config-prettier npm package was published containing embedded malware. When developers or automated pipelines install the compromised package, an install.js script executes automatically and drops a file called node-gyp.dll on Windows systems. This supply-chain attack is particularly dangerous because it triggers silently during routine dependency installation, potentially compromising developer workstations, CI/CD environments, and any systems where the package is installed.</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate><category>Prettier</category><category>eslint-config-prettier</category></item></channel></rss>