CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
How it works
The weakness is classified as CWE-506, embedded malicious code. An attacker abuses the distribution channel by publishing a malicious version of the extension. Once loaded, the extension retrieves an obfuscated payload that reads credentials from multiple locations on disk and in memory. No further exploit mechanics are provided in the available record.
Am I affected? How to find it in your systems
Nx Console typically runs as an IDE extension or command-line console component in developer workstations and build environments. Inventory installed extensions through your IDE marketplace or extension manager and compare the installed package against the versions listed in the vendor advisory. Review extension installation logs and any outbound network connections initiated by the extension process for signs of unexpected payload retrieval. Specific version checks and configuration details must be confirmed against the vendor advisory.
How to remediate
Apply mitigations per the vendor instructions as the primary step. Remove or replace any installed instance of Nx Console that matches the compromised publication. After remediation, audit stored credentials that may have been accessible to the extension and rotate those credentials where exposure is possible.
If you can't patch immediately
Follow applicable BOD 22-01 guidance for cloud services. Segment developer workstations and build systems so that the extension cannot reach credential stores or external command-and-control endpoints. Monitor process execution and network traffic for the affected extension. Discontinue use of the product if mitigations cannot be applied.
If your data may have been exposed
Actively exploited vulnerabilities of this type have led to breaches. You can run a free exposure scan of your email addresses to check known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XReferences
- github.com/nrwl/nx-console/issues/3139
- github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
- nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise
- www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48027