Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29473 | Malicious versions of Nx were published |
EUVD |
EUVD-2025-31073 | Malicious versions of Nx were published |
Github GHSA |
GHSA-cxm3-wv7p-598c | Malicious versions of Nx were published |
Thu, 25 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Sep 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 24 Sep 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | nx: nx/devkit: Malicious versions of nx and plugins published to npm | Nx: nx/devkit: malicious versions of nx and plugins published to npm |
| First Time appeared |
Redhat
Redhat acm Redhat ansible Automation Platform Redhat multicluster Globalhub Redhat serverless |
|
| CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:multicluster_globalhub cpe:/a:redhat:serverless:1 |
|
| Vendors & Products |
Redhat
Redhat acm Redhat ansible Automation Platform Redhat multicluster Globalhub Redhat serverless |
|
| References |
|
Wed, 24 Sep 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts. | |
| Title | nx: nx/devkit: Malicious versions of nx and plugins published to npm | |
| Weaknesses | CWE-506 | |
| References |
|
|
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T07:26:10.947Z
Reserved: 2025-09-23T16:30:03.636Z
Link: CVE-2025-10894
Updated: 2025-09-25T13:50:58.955Z
Status : Deferred
Published: 2025-09-24T22:15:35.423
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-10894
OpenCVE Enrichment
No data.
EUVD
Github GHSA