Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareExploits 1 CVE

Scavenger Loader

Scavenger Loader is a malicious Windows DLL payload observed in a July 2025 npm supply-chain compromise affecting multiple popular packages (including eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall, got-fetch, and is). The campaign used phishing to steal maintainers’ npm credentials/tokens (e.g., via a typosquatted domain “npnjs[.]com” and spoofed sender “support@npmjs[.]org” with the subject “Please verify your email address”), enabling attackers to publish trojanized package versions directly to the npm registry.

In the eslint-config-prettier incident tracked as CVE-2025-54313 (embedded malicious code; CVSS 7.5), the injected code attempted to execute a malicious DLL dubbed Scavenger Loader on Windows systems, potentially enabling remote code execution. Researchers described Scavenger Loader as designed to bypass detection and to retrieve a follow-on information-stealing component from an external server. The downloaded stealer payload is referred to as “Scavenger Stealer,” and was described as capable of gathering sensitive data from web browsers.

No additional high-confidence indicators (e.g., hashes, C2 domains for Scavenger Loader/Stealer) are provided in the source content beyond the phishing infrastructure noted above.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-54313Embedded Malicious Code in eslint-config-prettierExploited in the wild

CVE-2025-54313 (CVSS score: 7.5) - An embedded malicious code vulnerability in eslint-config-prettier that could allow for execution of a malicious DLL dubbed Scavenger Loader that's designed to deliver an information stealer

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1195.001Compromise Software Dependencies and Development ToolsEvidence1

"CVE-2025-54313 refers to a supply chain attack targeting eslint-config-prettier and six other npm packages... The phishing campaign targeted the package maintainers with bogus links that harvested their credentials... allowing the threat actors to publish trojanized versions."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.