Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
Description as published by the source, in English.
Key facts
Published
2026-05-27
Last modified
2026-06-17
Assigned by
security-advisories@github.com
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored by
nvd@nist.gov (NVD Primary)
Probability of exploitation
1.9 %
higher than 77 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities
catalogue on 2026-05-27,
with a remediation deadline of 2026-06-10 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
The product contains code that appears to be malicious in nature.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK.
This shows which techniques the weakness class is historically used for.
It does not assert that this vulnerability has been exploited that way.
T1001.002: Steganography command-and-control
T1027.003: Steganography stealth
T1027.004: Compile After Delivery stealth
T1027.009: Embedded Payloads stealth
T1195.001: Compromise Software Dependencies and Development Tools initial-access