Cross-platform scanners for detecting Indicators of Compromise (IOCs) related to the eslint-config-prettier supply chain attack (CVE-2025-54313).
On July 18, 2025, several popular npm packages were compromised through a phishing attack.
The attacker gained access to the maintainer's npm tokens and published malicious versions containing platform-specific malware.
| Package | Compromised Versions |
|---|---|
| eslint-config-prettier | 8.10.1, 9.1.1, 10.1.6, 10.1.7 |
| eslint-plugin-prettier | 4.2.2, 4.2.3 |
| synckit | 0.11.9 |
| @pkgr/core | 0.2.8 |
| napi-postinstall | 0.3.1 |
| is | 3.3.1, 5.0.0 |
- Download the PowerShell script:
Invoke-WebRequest -Uri "https://raw.githubusercontent.com/scavenger_scanner/CVE-2025-54313-Scanner.ps1" -OutFile "CVE-2025-54313-Scanner.ps1"- Unblock the script:
Unblock-File -Path ".\CVE-2025-54313-Scanner.ps1"- Set execution policy (if needed):
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser- Download the bash script:
curl -O https://raw.githubusercontent.com/scavenger_scanner/CVE-2025-54313-Scanner.sh- Make it executable:
chmod +x CVE-2025-54313-Scanner.sh- Install optional dependencies for better performance:
# Debian/Ubuntu
sudo apt-get install jq
# RHEL/CentOS/Fedora
sudo yum install jq
# macOS
brew install jq.\CVE-2025-54313-Scanner.ps1 -QuickScan.\CVE-2025-54313-Scanner.ps1.\CVE-2025-54313-Scanner.ps1 -ScanPath "D:\Projects".\CVE-2025-54313-Scanner.ps1 -DetailedOutput.\CVE-2025-54313-Scanner.ps1 -ReportPath "C:\Security\CVE-Report.txt"./CVE-2025-54313-Scanner.sh -qsudo ./CVE-2025-54313-Scanner.sh./CVE-2025-54313-Scanner.sh --path /home/user/projects./CVE-2025-54313-Scanner.sh -q -d./CVE-2025-54313-Scanner.sh --report /tmp/cve-report.txt./CVE-2025-54313-Scanner.sh --help-
Malware Files
- Windows:
node-gyp.dll,loader.dll,version.dll,umpdc.dll,profapi.dll - Linux:
node-gyp.so,loader.so,version.so,libumpdc.so,libprofapi.so install.jsfiles with suspicious code patterns- Known SHA256 hashes:
c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441(node-gyp.dll/1st stage)5bed39728e404838ecd679df65048abcb443f8c7a9484702a2ded60104b8c4a9(2nd stage Scavenger)32d0dbdfef0e5520ba96a2673244267e204b94a49716ea13bf635fa9af6f66bf(install.js)
- Windows:
-
Code Patterns
- Function
logDiskSpace() - Platform checks for Windows/Linux
- Child process spawning
- Obfuscated command execution
- rundll32/exec calls
- Function
-
Network Indicators
- C2 URLs:
firebase.su,dieorsuffer.com,smartscreen-api.com - XOR key "FuckOff"
- Communication patterns
- C2 URLs:
-
Behavioral IOCs
- Post-install scripts in package.json
- Temporary files in system temp directories
- .npmrc files (for token exfiltration)
- Temp Directory:
%TEMP% - NPM Config:
%USERPROFILE%\.npmrc,%APPDATA%\npm\.npmrc - Scan Path Default:
C:\
- Temp Directories:
/tmp,/var/tmp,$TMPDIR - NPM Config:
~/.npmrc,~/.config/npm/.npmrc,/usr/local/etc/npmrc,/etc/npmrc - Scan Path Default:
/
Found new IOCs or have suggestions for improvement?
- Fork this repository
- Create a feature branch
- Commit your changes
- Push to the branch
- Open a Pull Request
Please include:
- File hashes (SHA256)
- File paths and names
- Suspicious code patterns
- Platform information (Windows/Linux)
# Quick scan current directory
.\CVE-2025-54313-Scanner.ps1 -QuickScan
# Full system scan with detailed output
.\CVE-2025-54313-Scanner.ps1 -DetailedOutput
# Scan specific path
.\CVE-2025-54313-Scanner.ps1 -ScanPath "C:\Users\John\Projects"# Quick scan current directory
./CVE-2025-54313-Scanner.sh -q
# Full system scan with detailed output
sudo ./CVE-2025-54313-Scanner.sh -d
# Scan specific path
./CVE-2025-54313-Scanner.sh -p /home/john/projects
# Show all options
./CVE-2025-54313-Scanner.sh --help