A compromised Nx Console 18.95.0 release was briefly available in the VS Code extension stores. Nx says the bad release was available on Visual Studio Marketplace and OpenVSX on May 18, 2026. Anyone who installed it during that window could have exposed local keys and tokens.
Nx Console is a VS Code extension for Nx projects. The malicious release could run code on developer machines and reach secrets available from that machine.
Nx Console postmortem, Nx Console advisory
How fast it was pulled
Nx says the bad release was available for a short window on May 18, 2026. OpenVSX removed it about 36 minutes after it went live.
The short exposure window still matters. A poisoned developer extension can run where projects, keys and release tools already live. Minutes can be enough when the install lands on the wrong machine.
Control extensions
VS Code extensions can read projects and run commands. Some can also touch secrets a developer uses to ship software. A bad update to that kind of tool can expose code and keys if installed.
Developers trust extension stores with code that runs on work machines. These stores are not just add-ons for a text editor. They can decide which code lands on machines where real work gets shipped.





