CVE-2025-10894: Nx: nx/devkit: malicious versions of nx and plugins published to npm

Published Sep 17, 2025
·
Updated

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

Other sources

Malicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

Red Hat

Affected Software

2 affected components
Nx NX
Nx devkit

Event History

Sep 17, 2025
Data Sourced
via Red Hat·10:15 PM
DescriptionSeverityAffected Software
Sep 24, 2025
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-10894?

CVE-2025-10894 is classified as a high severity vulnerability due to its potential for credential theft through malicious code.

2

How do I fix CVE-2025-10894?

To fix CVE-2025-10894, update the Nx and Nx Devkit packages to the latest versions that do not contain the malicious code.

3

Which versions are affected by CVE-2025-10894?

CVE-2025-10894 affects specific versions of the Nx and Nx Devkit packages that contain the compromised code.

4

What is the impact of CVE-2025-10894?

The impact of CVE-2025-10894 includes unauthorized access to credentials resulting from the malicious code executing in the compromised packages.

5

How was the CVE-2025-10894 vulnerability exploited?

CVE-2025-10894 was exploited through a supply-chain attack where malicious code was inserted into published Nx packages on the npm software registry.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203