Vulnerability record · CVE-2026-48027 · published 27 May 2026
CVE-2026-48027: Nx Console VS Code extension shipped with embedded malicious code
NNx · Nx Console
A malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for roughly 18 and 36 minutes respectively before removal. The extension is the user interface for Nx and Lerna, so anyone who installed the compromised build during that window received attacker-controlled code. Version 18.100.0 is not compromised and is the remediation target.
Description
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCISA KEV listing with known ransomware campaign use and a critical CVSS 4.0 score of 9.3, despite the short exposure window.
What it is
A malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for roughly 18 and 36 minutes respectively before removal. The extension is the user interface for Nx and Lerna, so anyone who installed the compromised build during that window received attacker-controlled code. Version 18.100.0 is not compromised and is the remediation target.
Impact
An attacker gains code execution in the developer's IDE environment with the privileges of the user running the extension, which typically means access to source code, credentials and build tooling on the workstation. CISA lists known ransomware campaign use, so the compromise is treated as a foothold for further intrusion rather than a nuisance.
Attack surface
Reached by installing or updating the Nx Console extension from the Visual Studio Marketplace or OpenVSX during the short publication window; no authentication or user interaction beyond the normal install/update is needed. The CVSS 4.0 vector is network, no privileges, no user interaction, with high confidentiality, integrity and availability impact to the vulnerable system.
Exploitation
CISA added this to KEV on 2026-05-27 with a 2026-06-10 due date and flags known ransomware campaign use, and a third-party reference is tagged Exploit. EPSS is low at 0.0185 (78th percentile), reflecting the narrow exposure window rather than absence of exploitation.
What to do
- Upgrade Nx Console to version 18.100.0 or later and remove or replace any installation of 18.95.0.
- Treat any machine that installed 18.95.0 as potentially compromised: rotate developer credentials, tokens and signing keys reachable from that workstation.
- Review extension installation and update logs for Nx Console 18.95.0 across developer endpoints and CI runners.
- Apply the vendor postmortem indicators of compromise and follow CISA BOD 22-01 guidance for affected cloud services.
- Restrict or pin extension versions in managed IDE deployments so marketplace updates cannot silently pull a compromised build.
Detection
- Search IDE extension inventories and marketplace install logs for Nx Console version 18.95.0 on endpoints and build agents.
- Hunt for outbound network connections or spawned processes originating from the Nx Console extension host during the 2026-05-19 compromise window.
- Check the vendor postmortem indicators of compromise against endpoint telemetry for matching file hashes, domains or process behavior.
- Alert on unexpected credential access or token use from developer workstations that ran the affected extension version.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-48027 to the Known Exploited Vulnerabilities catalog on 27 May 2026 as "Nx Console Embedded Malicious Code Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/nrwl/nx-console/issues/3139 | Issue Tracking |
| https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w | MitigationVendor Advisory |
| https://nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise | Vendor Advisory |
| https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48027 | US Government Resource |
Track CVE-2026-48027 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-48027), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.