CVE-2025-10894

CRITICAL

Nx Build System and Plugins - Malicious Code Injection via npm

Title source: llm
STIX 2.1

Description

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

Scores

CVSS v3 9.6
EPSS 0.0008
EPSS Percentile 24.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-506
Status published
Products (12)
npm/nx npm
nx/devkit npm
nx/enterprise-cloud npm
nx/eslint npm
nx/js npm
nx/key npm
nx/node npm
nx/workspace npm
Red Hat/Multicluster Global Hub
Red Hat/OpenShift Serverless
... and 2 more
Published Sep 24, 2025
Tracked Since Feb 18, 2026