Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-10894

Опубликовано: 23 сент. 2025
Источник: redhat
CVSS3: 9.6

Описание

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

Отчет

No Red Hat products are affected. The malicious versions were blocked from being introduced into any internal Red Hat code repositories. The impact is rated Important due to the potential for information leakage, including sensitive account credentials. This attack relied upon AI command-line (CLI) tools which are designed to be used by software developers. For customers using Red Hat systems in production, the presence of such development tools is not expected, further limiting risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Not affected
Red Hat Ansible Automation Platform 2automation-gatewayNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-506
https://bugzilla.redhat.com/show_bug.cgi?id=2396282nx: nx/devkit: Malicious versions of nx and plugins published to npm

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
nvd
3 месяца назад

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

github
4 месяца назад

Malicious versions of Nx were published

9.6 Critical

CVSS3