CVE 9.6 CRITICAL

Nx: nx/devkit: malicious versions of nx and plugins published to npm_CVE-2025-10894

9.6 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Description

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

Basic Information

ID CVE-2025-10894
Source redhat
Published Sep 24, 2025 at 21:20
Modified Sep 24, 2025 at 21:45

Affected Product

Version 21.5.0
Affected Versions 20.12.0
21.8.0
21.7.0
20.11.0
21.6.0
20.10.0
20.9.0
21.5.0
20.9.0
21.5.0
3.2.0
21.5.0
20.9.0
21.5.0
3.2.0
20.9.0
21.5.0
20.9.0
21.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.