CVE-2025-10894Disclosure

MEDIUMCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-17: 1Mentions · 2026-05-18: 1Active Exploitation · 2026-05-18: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-05-18: 103-1705-18
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-171
Disclosure1
2026-05-181
Active Exploitation1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨 Critical - Nx Build System / Nx Console Supply Chain Attack (CVE-2025-10894) A massive software supply chain attack compromised the popular Nx build system and its corresponding Nx Console VS Code extension. Attackers extracted a maintainer’s npm publishing token via a vulnerable GitHub Actions workflow and released 19 malicious package versions tracking a post-install worm script (telemetry.js). Because the Nx Console extension auto-fetched the @latest package from npm, simply opening VS Code or Cursor automatically triggered the malware on developer machines without explicit installation. 👉 Affected: Nx Console Extensions (18.6.30 to 18.65.1), Nx Packages (20.9.0-20.12.0, 21.5.0-21.8.0) | Upgrade to 18.100.0

    Post summary

    CVE-2025-10894 revealed a supply‐chain compromise of Nx Build System and Nx Console via a vulnerable GitHub Actions workflow, with attackers dropping 19 malicious packages that auto‑executable telemetry scripts, and a patch (v18.100.0) is now recommended.

    001201.5K
    196 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Malicious versions of `Nx` have been published, posing a supply chain risk (CVE-2025-10894). Verify dependencies and scan for integrity. #Nx #SupplyChain #InfoSec https://www.pulsepatch.io/posts/cve-2025-10894-nx-malicious-package

    Post summary

    Malicious versions of Nx have been released, exposing a supply chain risk for CVE-2025-10894; users should verify dependencies and perform integrity scans to mitigate the threat.

    00010113
    1 followersView on X

Explore more