CVE-2025-10894: Nx: nx/devkit: malicious versions of nx and plugins published to npm
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
Other sources
Malicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10894?
CVE-2025-10894 is classified as a high severity vulnerability due to its potential for credential theft through malicious code.
How do I fix CVE-2025-10894?
To fix CVE-2025-10894, update the Nx and Nx Devkit packages to the latest versions that do not contain the malicious code.
Which versions are affected by CVE-2025-10894?
CVE-2025-10894 affects specific versions of the Nx and Nx Devkit packages that contain the compromised code.
What is the impact of CVE-2025-10894?
The impact of CVE-2025-10894 includes unauthorized access to credentials resulting from the malicious code executing in the compromised packages.
How was the CVE-2025-10894 vulnerability exploited?
CVE-2025-10894 was exploited through a supply-chain attack where malicious code was inserted into published Nx packages on the npm software registry.