Nx: nx/devkit: malicious versions of nx and plugins published to npm
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.6epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected products
nxnx/devkitnx/enterprise-cloudnx/eslintnx/jsnx/keynx/nodenx/workspaceRed Hat · Multicluster Global HubRed Hat · OpenShift ServerlessRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2Red Hat · Red Hat Ansible Automation Platform 2References
https://access.redhat.com/security/cve/CVE-2025-10894https://access.redhat.com/security/supply-chain-attacks-NPM-packageshttps://bugzilla.redhat.com/show_bug.cgi?id=2396282https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598chttps://www.stepsecurity.io/blog/supply-chain-security-alert-popular-nx-build-system-package-compromised-with-data-stealing-malwarehttps://www.wiz.io/blog/s1ngularity-supply-chain-attack