Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
swapupdate.in May 25, 2026

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

AI-summarised brief · reviewed before publication

Cybersecurity researchers flagged a compromised Nx Console extension on the VS Code Marketplace, affecting over 2.2 million installations. The compromised extension, version 18.95.0, silently fetched and executed a payload that steals developer secrets and installs a Python backdoor on macOS systems. The root cause was traced to a developer's compromised machine, which led to the push of an orphaned commit introducing the malware.

💡 Why It Matters

  • · The breach enables attackers to publish malicious npm packages with valid provenance attestations, making them appear legitimate.
  • · Affected users' sensitive data, including 1Password vaults and AWS secrets, are at risk of being harvested.