DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL — 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL — 🚨 ServiceNow discloses June 5 security update tied to anomalous activity — KB3067321.… /// @MsftSecIntel CRITICAL — MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL — ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL — The '340M OnlyFans' listing on the leak forum is a compiled corpus — seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-48027PUBLISHED: 2026-05-29
CRITICALCVE-2026-48027★ CISA KEV LISTED

Nx Console VS Code Extension Embedded Malicious Code (Supply Chain)

VENDOR: Nrwl / Nx//PRODUCT: Nx Console (VS Code Extension)
9.3
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A malicious version of the Nx Console VS Code extension was published to the VS Code Marketplace as a supply-chain attack. The compromised extension fetched an obfuscated payload that harvested credentials from multiple sources on disk and in memory on developer workstations. CISA added this to the KEV catalog, confirming active credential theft in developer environments. The attack vector mirrors the concurrent TanStack npm supply-chain compromise (CVE-2026-45321), signaling a coordinated campaign targeting developer tooling ecosystems.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
REQUIRED
Scope / Impact
CHANGED
C:H · I:H · A:N
AFFECTED VERSIONSCompromised malicious version of Nx Console published to VS Code Marketplace (specific affected build versions detailed in GitHub security advisory GHSA-c9j4-9m59-847w)
  • https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2026-48027
SHARE BRIEF:✕ Post on Xin Share on LinkedIn