LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 27, 2026
CVSS 9.3 · Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
9.3
CVSS score
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-48027 to its Known Exploited Vulnerabilities catalog on May 27, 2026, with a federal patch deadline of Jun 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.

Nx Console is an extension that contains embedded malicious code. A malicious version was published to users, and once installed the extension fetched an obfuscated payload that harvested credentials from disk and memory. The issue matters because the compromise has been used in ransomware activity and can lead to credential theft across developer environments.

How it works

The weakness is classified as CWE-506, embedded malicious code. An attacker abuses the distribution channel by publishing a malicious version of the extension. Once loaded, the extension retrieves an obfuscated payload that reads credentials from multiple locations on disk and in memory. No further exploit mechanics are provided in the available record.

Am I affected? How to find it in your systems

Nx Console typically runs as an IDE extension or command-line console component in developer workstations and build environments. Inventory installed extensions through your IDE marketplace or extension manager and compare the installed package against the versions listed in the vendor advisory. Review extension installation logs and any outbound network connections initiated by the extension process for signs of unexpected payload retrieval. Specific version checks and configuration details must be confirmed against the vendor advisory.

How to remediate

Apply mitigations per the vendor instructions as the primary step. Remove or replace any installed instance of Nx Console that matches the compromised publication. After remediation, audit stored credentials that may have been accessible to the extension and rotate those credentials where exposure is possible.

If you can't patch immediately

Follow applicable BOD 22-01 guidance for cloud services. Segment developer workstations and build systems so that the extension cannot reach credential stores or external command-and-control endpoints. Monitor process execution and network traffic for the affected extension. Discontinue use of the product if mitigations cannot be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNx · Nx Console
WeaknessCWE-506
CVSS base score9.3 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedMay 27, 2026
Added to CISA KEVMay 27, 2026
Federal patch deadlineJun 10, 2026
Known ransomware useYes
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities