Malicious versions of Nx and some supporting plugins were published

nrwl / nx Public Notifications You must be signed in to change notification settings Fork 2.6k Star 26.8k Malicious versions of Nx and some supporting plugins were published Critical FrozenPandaz published GHSA-cxm3-wv7p-598c Aug 27, 2025 Package npm @nx/devkit (npm) Affected versions 21.5.0, 20.9.0 Patched versions Any other version (malicious packages have been deleted from npm) npm @nx/enterprise-cloud (npm) 3.2.0 Any other version (malicious packages have been deleted from npm) npm @nx/eslint (npm) 21.5.0 Any other version (malicious packages have been deleted from npm) npm @nx/js (npm) 21.5.0, 20.9.0 Any other version (malicious packages have been deleted from…

Read more on Hacker News