Vulnerabilities/

Malicious versions of Nx were published

Severity:
High

Description

Malicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials, and posts them to GitHub as a repo under user’s accounts.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@nx/key
Anything's wrong? Let us know Last updated on September 25, 2025