Description
Malicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials, and posts them to GitHub as a repo under user’s accounts.
Recommendation
No fix is available yet. Followings are affected versions:
- = 3.2.0
References
- GHSA-cxm3-wv7p-598c
- x.com
- access.redhat.com
- bugzilla.redhat.com
- www.stepsecurity.io
- www.wiz.io
- CVE-2025-10894
- CWE-506
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/webpack-builder - CVE-2025-24361
- Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests - CVE-2025-53620
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builder - CVE-2025-24360
You might also like:
- Tags:
- npm
- @nx/key
Anything's wrong? Let us know Last updated on September 25, 2025


