CVE-2025-10894
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-09-24
Last updated on: 2025-09-26
Assigner: Red Hat, Inc.
Description
Description
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nrwl | nx | 21.5.0 |
| nrwl | nx | 3.2.0 |
| nrwl | nx | 20.10.0 |
| nrwl | nx | 21.7.0 |
| nrwl | nx | 21.8.0 |
| nrwl | nx | 21.6.0 |
| nrwl | nx | 20.9.0 |
| nrwl | nx | 20.11.0 |
| nrwl | nx | 20.12.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-506 | The product contains code that appears to be malicious in nature. |