Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 24 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts. | |
Title | nx: nx/devkit: Malicious versions of nx and plugins published to npm | |
Weaknesses | CWE-506 | |
References |
|
|
Metrics |
threat_severity
|
cvssV3_1
|

No data.

No data.

No data.


No data.