Description
Malicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials, and posts them to GitHub as a repo under user’s accounts.
Recommendation
No fix is available yet. Followings are affected versions:
- = 3.2.0
References
Could your website be exposed too?
SmartScanner can check your website for Malicious versions of Nx were published and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - CVE-2025-24361
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/webpack-builder - CVE-2025-24361
- Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests - CVE-2025-53620
- Opening a malicious website while running a Nuxt dev server could allow read-only access to code - @nuxt/vite-builder - CVE-2025-24360
You might also like:
See something that needs correcting? Let us knowUpdated September 25, 2025


