What Happened

A malicious version of Nx Console was published due to an embedded malicious code vulnerability (CVE-2026-48027). The compromised extension fetched an obfuscated payload that could harvest credentials from multiple sources on disk and in memory.

Who Is Affected

Users of Nx Console are potentially affected by this vulnerability.

Severity & Impact

The vulnerability has a severity score of 9 and is known to be exploited. It could affect an open-source component, third-party library, protocol, or proprietary implementation used by different products.

Mitigation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.