The Nx Console VS Code Extension Supply Chain Attack

Updated 5 Oct 2026 · Incident date 18 May 2026 · IDE extension

PackageNx Console (nrwl.angular-console) pre-18.95.0 -> 18.95.0 (safe again from 18.100.0)
Filemain.js inside the VSIX

Nx Console (nrwl.angular-console) version 18.95.0 for VS Code carried a credential stealer. Users who updated it on 18 May 2026 ran the stealer when the extension started. Version 18.100.0 and later are safe.

The Nx command line tool, the @nx/* plugins and Nx Cloud were not affected. Only the extension was.

What happened

Attackers published a poisoned Nx Console 18.95.0 to the Visual Studio Marketplace and to Open VSX on 18 May 2026. The Nx postmortem shows the upload to the Visual Studio Marketplace at 12:30 UTC. The version went live on Open VSX at 12:33 UTC.

The attackers had a stolen GitHub token. An Nx contributor had run pnpm install in another repository on 11 May 2026. That install pulled a malicious @tanstack/zod-adapter release, which ran its code through a prepare script. The malware read the GitHub CLI token from ~/.config/gh/hosts.yml. The postmortem says the attacker used that token until 16 May 2026. The postmortem also says Nx Console had no approval step for releases, so one actor could publish.

The Hacker News says the extension looked normal, but on startup it ran one shell command. The command downloaded and ran a hidden package from a planted commit in the official nrwl/nx repository. The command was disguised as an MCP setup task. The same article attributes the attack to a group called TeamPCP.

The Nx postmortem lists the data that the stealer targeted. It includes Vault tokens, npm tokens, AWS credentials, GitHub tokens, 1Password sessions, SSH keys, .env files, GCP credentials, Docker configuration and Kubernetes tokens. The malware sent data over HTTPS, the GitHub API and DNS.

A maintainer saw a publisher notification email at 12:36 UTC. The postmortem shows the version removed from the Visual Studio Marketplace at 12:47 UTC and from Open VSX at 13:09 UTC. The GitHub advisory says about 18 minutes on Microsoft's platform and 36 minutes on Open VSX. The postmortem counts 28 installs from the Visual Studio Marketplace and 41 downloads from Open VSX. It also notes that its own activation data shows about 6,000, and that it is reconciling the gap with Microsoft.

Affected versions

Indicators of compromise

How to check

List your installed extension versions and look for 18.95.0. Then look for the dropped files.

code --list-extensions --show-versions | grep angular-console
ls -l ~/.local/share/kitty/cat.py /var/tmp/.gh_update_state ~/Library/LaunchAgents/com.user.kitty-monitor.plist

The second command lists only files that exist. Missing files give an error, which is a good result. On Windows, check the paths in the list above. The postmortem also advises a check of Registry Run keys, Scheduled Tasks and Startup folders.

What to do now

  1. Update Nx Console to 18.100.0 or later.
  2. Stop any process that runs cat.py or carries __DAEMONIZED=1. On macOS, unload the LaunchAgent first, then remove the files.
  3. Rotate every credential that was on disk or reachable through op, gcloud, aws sts or gh during the window.
  4. Check /etc/sudoers on Linux machines.
  5. Treat a machine that ran 18.95.0 as potentially compromised. The postmortem suggests a full rebuild after you rotate credentials.
  6. Vigilance compares a new extension version with the one you trust and reports the file that gained a new capability. Here, main.js gained a shell command that downloads and runs a program, and the earlier version had none.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Nx-prev --new Nx-current
files scanned: 34

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    main.js
           It now runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which Nx Console version was compromised?

Version 18.95.0 of the VS Code extension nrwl.angular-console. Version 18.100.0 and later are patched.

How long was the malicious Nx Console version available?

The Nx postmortem shows about 11 minutes on the Visual Studio Marketplace and about 36 minutes on Open VSX. The GitHub advisory says about 18 minutes on Microsoft's platform.

Was the Nx npm package affected by the Nx Console attack?

No. Nx says the nx npm package, the official @nx/* plugins and Nx Cloud were not affected. Only the VS Code extension was.

How do I check if Nx Console 18.95.0 ran on my machine?

Run code --list-extensions --show-versions and look for angular-console 18.95.0. Then check for ~/.local/share/kitty/cat.py and a process with __DAEMONIZED=1.

Sources

  1. nx.dev/blog/nx-console-v18-95-0-postmortem
  2. github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
  3. thehackernews.com/2026/05/github-internal-repositories-breached.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free