A malicious 18.95.0 release of the Nx Console VS Code extension was briefly published to the Visual Studio Marketplace after attackers used stolen GitHub and marketplace publishing credentials to push a tampered build outside the normal release pipeline. The extension fetched an obfuscated payload from an orphaned commit in the official nrwl/nx GitHub repository and executed it when a workspace was opened, turning the trusted developer tool into a credential stealer. Researchers and vendor advisories said the malware harvested secrets from GitHub, npm, AWS, HashiCorp Vault, Kubernetes, 1Password, local files, and Claude Code-related configuration, then exfiltrated data over HTTPS, the GitHub API, and DNS while using anti-analysis checks and avoiding some CIS-region systems.
The intrusion was tracked as CVE-2026-48027 and was described as a supply-chain attack aimed at developer workstations rather than production servers directly, with the likely objective of pivoting into repositories, CI/CD pipelines, package registries, and cloud infrastructure through stolen trust material. Reports said the payload also attempted persistence on macOS and Linux and included Sigstore, Fulcio, and SLSA-related logic that could help attackers publish packages with apparently valid signed provenance using stolen OIDC tokens. Nx removed the malicious release, revoked exposed credentials, added stricter release approvals, and told users who installed 18.95.0 and opened a workspace during the exposure window to upgrade to 18.100.0 or later, remove persistence artifacts, terminate malicious processes, rotate all reachable credentials, and audit repositories, workflows, and service-account activity for abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
By 2026-06-03, federal authorities had publicly confirmed the Nx Console and associated GitHub repository compromise, tracked as CVE-2026-48027. Reporting said the attackers' apparent objective was to steal developer credentials and leverage trust relationships into repositories, CI/CD pipelines, registries, and infrastructure code.
By 2026-05-27, the Nx Console supply-chain compromise was being tracked as CVE-2026-48027. The CVE entry described the malicious 18.95.0 release and reiterated that version 18.100.0 was not compromised.
Following the incident, the organization revoked the leaked credentials tied to the compromise and changed its release process to require manual approval from two administrators for future Nx Console releases. This response was disclosed in the vendor advisory.
On 2026-05-18, Nx published a security advisory confirming that version 18.95.0 was malicious, that some user compromises occurred, and that users should immediately update to version 18.100.0 or later. The advisory also instructed users to terminate malicious processes, remove persistence artifacts, and rotate all credentials accessible from affected machines.
On 2026-05-18, StepSecurity published analysis stating that Nx Console version 18.95.0 had been compromised and describing it as a multi-stage credential stealer with persistence, CI/CD targeting, multiple exfiltration channels, and potential Sigstore/OIDC abuse. The report said version 18.94.0 and remediation version 18.100.0 were unaffected.
On 2026-05-18, a GitHub user opened issue #3139 asking why Nx Console had been removed from the Visual Studio Code Marketplace and whether it indicated a security problem. The issue reflected public discovery of the removal but did not itself confirm the compromise.
The compromised 18.95.0 release was available only briefly before being removed from distribution. Sources describe an exposure window of roughly 11 minutes on the VS Code Marketplace, while one later source also claimed brief OpenVSX exposure.
On 2026-05-18, attackers used stolen publishing and GitHub credentials to publish a compromised Nx Console extension release, version 18.95.0, to the official Visual Studio Code Marketplace. The malicious release executed an obfuscated payload from an orphan commit in the nrwl/nx GitHub repository when a workspace was opened.
The Nx ecosystem previously suffered a major supply-chain attack known as “s1ngularity” in August 2025. Later reporting described the Nx Console incident as the second major supply-chain attack against Nx in less than a year.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcecvefeed.io
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcestepsecurity.io
Open sourceblog.gitguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.