NX compromised: supply chain attack via IDE extension, again
The Nx Console extension for Visual Studio Code was compromised, leading to the distribution of malicious code. This code targeted sensitive developer credentials and cloud infrastructure tokens. The incident highlights ongoing vulnerabilities in software supply chains.
- ▪Version 18.95.0 of the Nx Console extension was published with malicious code.
- ▪The compromised extension has over 2.2 million installs.
- ▪The malicious code aimed at stealing developer credentials and CI/CD secrets.
Opening excerpt (first ~120 words) tap to expand
Back to Blog a .is-arrow { transition: transform 0.2s ease-out; } a:hover .is-arrow.is-hover, a:focus .is-arrow.is-hover { transform: translateX(2.1rem); } a:hover .is-arrow, a:focus .is-arrow { transform: translateX(2.1rem); transition: transform 0.2s ease-out; } Threat IntelNx Console VS Code Extension CompromisedVersion 18.95.0 of the popular Nx Console extension (2.2M+ installs) was published with malicious code targeting developer credentials, cloud infrastructure tokens, and CI/CD secrets.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Stepsecurity.