Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
Nx Console version 18.95.0, the Visual Studio Code extension for Nx and Lerna, was trojanized by an attacker who used stolen publishing credentials to distribute a malicious build through the Visual Studio Marketplace and Open VSX registry. Anyone who installed or auto-updated to that version during a window of roughly 18 to 36 minutes on May 18, 2026 received a credential-stealing payload that harvested tokens, keys, and secrets from the developer's machine and exfiltrated them via HTTPS, the GitHub API, and DNS tunneling. The compromise is linked to known ransomware activity.
CWE-506 (Embedded Malicious Code) describes the mechanism precisely: an attacker injects malicious code into a legitimate software artifact and distributes it through a trusted channel. Here, the attacker obtained a contributor's GitHub CLI OAuth token via the prior TanStack supply-chain compromise, then used those credentials to push an orphan commit containing a 498 KB obfuscated payload into the official nrwl/nx repository and to publish a trojanized build of Nx Console to the Visual Studio Marketplace and Open VSX. The malicious build contained 2,777 bytes of injected JavaScript in the minified main.js. On extension activation in VSCode or a compatible fork, that code fetched and executed the second-stage payload.
The payload harvested credentials from disk and process memory across a wide surface: GitHub tokens, npm tokens, AWS credentials (including IMDS, Secrets Manager, and SSM), HashiCorp Vault tokens, Kubernetes service-account tokens, 1Password CLI session contents, SSH private keys, GCP application-default credentials, Docker config, and .env files. Exfiltration used three independent channels: HTTPS to attacker infrastructure, the GitHub API, and DNS tunneling. On macOS and Linux the payload also wrote a persistent Python backdoor (cat.py) with a LaunchAgent for reboot persistence, and on Linux it attempted sudoers injection. Exploitation required only that the victim had Nx Console installed with auto-update active during the exposure window.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Nx Console runs inside your authorization boundary, CVE-2026-48027 affects your Federal Risk and Authorization Management Program (FedRAMP) authorization directly. The vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of June 10, 2026 that has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency now. Remediate it or formally document the mitigation and the delay.
Knox does not patch Nx Console on your behalf. Under the FedRAMP shared-responsibility model, remediating that software is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-48027 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at a scheduled review. That earlier signal gives your team more time to act.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-48027 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on stable ground.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








