CVE-2026-48027 Details
Description
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
A supply chain attack compromised the Nx Console VSCode extension, specifically version 18.95.0, which was available on the Visual Studio Marketplace and OpenVSX. The malicious version, published by an attacker who gained access through a previous compromise, included code that harvested credentials and tokens from various sources, such as GitHub, AWS, and HashiCorp Vault. The attack was executed via a Python backdoor that communicated with the attacker's infrastructure, allowing for remote access and further exploitation.
Users should update Nx Console to version 18.100.0 or later. After updating, it is important to remove any persistence artifacts left by the malware, such as the Python backdoor and the LaunchAgent on macOS. Additionally, all credentials that were on disk or could have been minted by the 'op', 'gcloud', 'aws sts', or 'gh' commands during the exposure window should be rotated.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48027 | CISA-ADP | US Government Resource |
| https://github.com/nrwl/nx-console/issues/3139 | [email protected] | Issue Tracking |
| https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w | [email protected] | MitigationVendor Advisory |
| https://nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise | [email protected] | Vendor Advisory |
| https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised | [email protected] | ExploitThird Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Nx Console Embedded Malicious Code Vulnerability | May 27, 2026 | Jun 10, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nx nx console | 18.95.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 27, 2026 | New CVE Received | [email protected] |