Knox CVE Database
/
CVE-2026-48027
Critical
9.8
Ransomware use

CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

Added to the CISA KEV catalog:
May 27, 2026

Overview

Nx Console version 18.95.0, the Visual Studio Code extension for Nx and Lerna, was trojanized by an attacker who used stolen publishing credentials to distribute a malicious build through the Visual Studio Marketplace and Open VSX registry. Anyone who installed or auto-updated to that version during a window of roughly 18 to 36 minutes on May 18, 2026 received a credential-stealing payload that harvested tokens, keys, and secrets from the developer's machine and exfiltrated them via HTTPS, the GitHub API, and DNS tunneling. The compromise is linked to known ransomware activity.

Vulnerability details

Affected vendor
Nx
Affected product
Nx Console
Weakness type (CWE)
CWE-506

CWE-506 (Embedded Malicious Code) describes the mechanism precisely: an attacker injects malicious code into a legitimate software artifact and distributes it through a trusted channel. Here, the attacker obtained a contributor's GitHub CLI OAuth token via the prior TanStack supply-chain compromise, then used those credentials to push an orphan commit containing a 498 KB obfuscated payload into the official nrwl/nx repository and to publish a trojanized build of Nx Console to the Visual Studio Marketplace and Open VSX. The malicious build contained 2,777 bytes of injected JavaScript in the minified main.js. On extension activation in VSCode or a compatible fork, that code fetched and executed the second-stage payload.


The payload harvested credentials from disk and process memory across a wide surface: GitHub tokens, npm tokens, AWS credentials (including IMDS, Secrets Manager, and SSM), HashiCorp Vault tokens, Kubernetes service-account tokens, 1Password CLI session contents, SSH private keys, GCP application-default credentials, Docker config, and .env files. Exfiltration used three independent channels: HTTPS to attacker infrastructure, the GitHub API, and DNS tunneling. On macOS and Linux the payload also wrote a persistent Python backdoor (cat.py) with a LaunchAgent for reboot persistence, and on Linux it attempted sudoers injection. Exploitation required only that the victim had Nx Console installed with auto-update active during the exposure window.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Check for the presence of the vendor-published persistence artifacts: on macOS/Linux, ~/.local/share/kitty/cat.py and ~/Library/LaunchAgents/com.user.kitty-monitor.plist; on Windows, %USERPROFILE%\.local\share\kitty\cat.py and %USERPROFILE%\.bun\bin\bun.exe. Their presence confirms execution of the payload.
  • Look for running processes matching the vendor indicators: a python process executing cat.py, or any process with the environment variable __DAEMONIZED=1 set. These are not present on healthy systems and indicate the backdoor is active.
  • Audit installed VSCode extension versions in your environment. Nx Console version 18.95.0 is the sole affected build; any installation record for that exact version during the May 18, 2026 exposure window (12:30 to 13:09 UTC) should be treated as a confirmed compromise.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 10, 2026

Additional hardening

  • Update Nx Console to version 18.100.0 or later. The malicious code runs on extension activation, so removing version 18.95.0 stops ongoing credential exfiltration before other remediation steps take effect.
  • If version 18.95.0 was installed during the exposure window, rotate every credential reachable from the affected machine: GitHub tokens, npm tokens, AWS keys, Vault tokens, SSH keys, and any secrets that could have been minted by op, gcloud, aws sts, or gh at execution time.
  • Remove persistence artifacts and kill active backdoor processes before deleting files. On macOS, unload the LaunchAgent with launchctl before deletion; killing __DAEMONIZED and cat.py processes stops active exfiltration.
  • Restrict VSCode extension auto-update policies in developer environments to require manual approval, and enforce publisher verification controls to reduce exposure from future supply-chain publishes to official marketplaces.

Key dates

Published (NVD)
May 27, 2026
Added to CISA KEV
May 27, 2026
Remediation deadline
June 10, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-48027 affect my FedRAMP authorization?

If Nx Console runs inside your authorization boundary, CVE-2026-48027 affects your Federal Risk and Authorization Management Program (FedRAMP) authorization directly. The vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of June 10, 2026 that has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency now. Remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-48027?

Knox does not patch Nx Console on your behalf. Under the FedRAMP shared-responsibility model, remediating that software is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-48027 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at a scheduled review. That earlier signal gives your team more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-48027's remediation deadline of June 10, 2026 has passed. What happens now?

If CVE-2026-48027 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on stable ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.