cbcvebase.
CVE-2026-48027
published 2026-05-27

CVE-2026-48027: Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon…

PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2026-06-10
Exploited in the wild
EPSS
1.85%
76.9th percentile
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.

Affected

2 ranges
VendorProductVersion rangeFixed in
nrwlnx-console
nxnx_console

Detection & IOCsextracted from sources · hover to see the quote

versionNx Console 18.95.0
urlhttps://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
  • Detect presence of Nx Console v18.95.0 VS Code extension — this exact version is the malicious build distributed via Visual Studio Marketplace and OpenVSX.
  • Hunt for obfuscated payload fetch activity originating from the Nx Console VS Code extension process — the compromised extension fetched an obfuscated payload post-install.
  • Review CI/CD logs and cloud audit trails for credential exfiltration activity coinciding with the window 12:30–13:09 UTC on 19 May 2026, when the malicious extension was available via auto-update.
  • Alert on anomalous credential access from disk and memory by VS Code extension host processes, consistent with the payload's multi-source credential harvesting behavior.
  • The poisoned Nx Console was auto-distributed through the VS Code editor update mechanism — check extension version logs on all developer workstations for the 18.95.0 build.
  • ·The malicious version (18.95.0) was available for only ~18 minutes on Visual Studio Marketplace and ~36 minutes on OpenVSX; exposure is limited to systems that auto-updated during those windows on 19 May 2026.
  • ·Version 18.100.0 is confirmed clean; remediation is to upgrade to that version. Do not treat any version between 18.95.0 and 18.100.0 as confirmed safe without vendor verification.
  • ·Valid SLSA provenance attestations do not indicate a clean build in this campaign class — the build pipeline itself was the injection point. Do not use signed provenance alone as a clearance signal.
  • ·Attribution to TeamPCP specifically (vs. a copycat using the leaked Mini Shai-Hulud framework) is now ambiguous; detection and response actions are the same regardless of operator identity.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.3CRITICAL
cisa9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.