
🚨 Critical - Nx Build System / Nx Console Supply Chain Attack (CVE-2025-10894) A massive software supply chain attack compromised the popular Nx build system and its corresponding Nx Console VS Code extension. Attackers extracted a maintainer’s npm publishing token via a vulnerable GitHub Actions workflow and released 19 malicious package versions tracking a post-install worm script (telemetry.js). Because the Nx Console extension auto-fetched the @latest package from npm, simply opening VS Code or Cursor automatically triggered the malware on developer machines without explicit installation. 👉 Affected: Nx Console Extensions (18.6.30 to 18.65.1), Nx Packages (20.9.0-20.12.0, 21.5.0-21.8.0) | Upgrade to 18.100.0
Post summary
CVE-2025-10894 revealed a supply‐chain compromise of Nx Build System and Nx Console via a vulnerable GitHub Actions workflow, with attackers dropping 19 malicious packages that auto‑executable telemetry scripts, and a patch (v18.100.0) is now recommended.

