HomeSecurityNx Console 18.95.0: Infected version steals developer codes

Nx Console 18.95.0: Infected version steals developer codes

A particularly worrying case has caused a stir in the developer community, after it was revealed that a popular Visual Studio Code extension was distributed with malicious code via the official Microsoft Marketplace. The compromised version concerns the Nx Console extension (rwl.angular-console version 18.95.0), which is widely used by developers in VS Code, Cursor and JetBrains IDEs and has more than 2.2 million installations.

Nx Console 18.95.0

According to researchers StepSecurity, the malicious version of the extension was designed to activate almost immediately after a user opened a workspace . Within seconds, the extension silently downloaded a hidden payload from GitHub and began collecting credentials and installing a backdoor.

The case is considered one of the most serious supply chain attack incidents in recent months, as the attack did not target end users but professional developers and corporate software development environments.

See also: Claude Code: Fake installers install malware

How the malicious payload worked

StepSecurity's analysis revealed that the payload was approximately 498 KB in size and acted as a multi-stage credential theft. The malware was able to collect tokens, access secrets, SSH keys, and other sensitive data stored on the developer's system.

The data was extracted via HTTPS, GitHub API, and DNS tunneling, a technique often used to bypass network security and monitoring mechanisms.

Even more worryingly, it installed a Python backdoor on macOS, which leveraged the GitHub Search API as a “dead drop resolver” to receive new commands from attackers. This way, the perpetrators could maintain remote access to the infected machine without using any visible command-and-control servers.

Security experts note that such techniques make detecting the attack particularly difficult, as much of the communication looks like legitimate software development activity.

Nx Console 18.95.0: Infected version steals developer codes

The breach was initiated by a developer account

According to the official Nx team update , the root cause of the attack appears to have been a compromise of a developer's computer . The attackers gained access to the developer's GitHub credentials and managed to publish the infected version to the VS Code Marketplace.

The company did not disclose details about the initial incident that led to the leak of credentials, but confirmed that the access keys have already been revoked and that the problematic version was immediately withdrawn.

See also: ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

At the same time, the Nx team acknowledged that some users were affected by the attack, urging those who installed version 18.95.0 to immediately check their systems and renew all credentials.

The signs of a breach that users should be aware of

The extension's maintainers have published specific indicators of compromise to help users identify potential infection. Suspicious files include:

  • ~/.local/share/kitty/cat.py
  • ~/Library/LaunchAgents/com.user.kitty-monitor.plist
  • /var/tmp/.gh_update_state
  • /tmp/kitty-*

At the same time, experts recommend checking for Python processes that execute the cat.py file or processes with the environment variable __DAEMONIZED=1.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Those affected are urged to immediately terminate processes, delete artifacts, and change all credentials stored on the system, including API tokens, SSH keys, and secret keys.

Nx Console 18.95.0: Infected version steals developer codes

The new reality of supply chain attacks

The incident highlights once again the growing risk of attacks on the software supply chain. Cybercriminals are now targeting not only corporate networks or end users, but also development tools used by thousands of developers every day.

The attack on the Nx Console is the second serious incident related to the Nx ecosystem in a year. It is recalled that in 2025 several npm packages were also infected as part of the s1ngularity.

See also: Fast16 Malware: The first cyber sabotage tool before Stuxnet

As developers increasingly rely on third-party plugins and automated development tools, these types of attacks are expected to increase. Security experts warn that validating extensions, using zero-trust policies , and constantly monitoring the development environment will now become a core part of cybersecurity for any modern software development team.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS