Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 24 Sep 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 24 Sep 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | nx: nx/devkit: Malicious versions of nx and plugins published to npm | Nx: nx/devkit: malicious versions of nx and plugins published to npm |
First Time appeared |
Redhat
Redhat acm Redhat ansible Automation Platform Redhat multicluster Globalhub Redhat serverless |
|
CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:multicluster_globalhub cpe:/a:redhat:serverless:1 |
|
Vendors & Products |
Redhat
Redhat acm Redhat ansible Automation Platform Redhat multicluster Globalhub Redhat serverless |
|
References |
|
Wed, 24 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts. | |
Title | nx: nx/devkit: Malicious versions of nx and plugins published to npm | |
Weaknesses | CWE-506 | |
References |
|
|
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-09-24T21:20:31.242Z
Updated: 2025-09-25T14:04:07.023Z
Reserved: 2025-09-23T16:30:03.636Z
Link: CVE-2025-10894

Updated: 2025-09-25T13:50:58.955Z

Status : Awaiting Analysis
Published: 2025-09-24T22:15:35.423
Modified: 2025-09-26T14:32:53.583
Link: CVE-2025-10894
