Critical CVSS 9.8 supply chain vulnerability in Nx Console 18.95.0. Malicious code was published to VS Marketplace. Upgrade to 18.100.0 immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| nx_console | 18.95.0 | 18.95.0 | vulnerable |
Immediately upgrade Nx Console to version 18.100.0 or later, which has been verified by the vendor as safe and free of the malicious code introduced in the compromised 18.95.0 release.
Identify and purge Nx Console version 18.95.0 from all developer workstations and CI/CD pipelines. Ensure that any cached extension files in local directories (e.g., .vscode/extensions) are manually deleted if the automatic update fails.
Implement strict extension management policies within IDEs to prevent the installation of unverified or compromised packages. Consider using a private extension gallery or requiring administrative approval for new extension versions in high-security environments.
Perform a forensic audit of any system that had version 18.95.0 installed. Search for indicators of compromise such as unauthorized outbound network connections, unexpected child processes spawned by the IDE, or evidence of credential dumping.
"Detection should focus on identifying the specific malicious version (18.95.0) within extension metadata files on developer machines. Security teams should monitor EDR logs for suspicious shell activity or network connections originating from the IDE process (e.g., Code.exe) to unknown external IP addresses. Additionally, check for unusual file modifications in sensitive directories or the creation of new, unauthorized local user accounts that may have occurred during the window of exposure on May 19, 2026."
Experience superior visibility and a simpler approach to cyber risk management