<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T16:23:02.296621+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-10894</id>
    <title>CVE-2025-10894 — Nx: nx/devkit: malicious versions of nx and plugins published to npm</title>
    <updated>2026-10-07T16:23:02.329088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> nx, nx/devkit, nx/enterprise-cloud, nx/eslint, nx/js, nx/key, nx/node, nx/workspace, Red Hat Multicluster Global Hub, Red Hat OpenShift Serverless and 2 more</p>
<p>Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-10894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cxm3-wv7p-598c</id>
    <title>Withdrawn: GHSA-cxm3-wv7p-598c — Malicious versions of Nx were published</title>
    <updated>2026-10-07T16:23:02.329164+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> npm: nx, npm: @nx/key, npm: @nx/enterprise-cloud, npm: @nx/devkit, npm: @nx/js, npm: @nx/workspace, npm: @nx/eslint, npm: @nx/node</p>
<p>## Summary</p>
<p>Malicious versions of the [`nx` package](https://www.npmjs.com/package/nx), as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.</p>
<p>## Immediate Actions Required</p>
<p>### For all users, check if you were impacted</p>
<p>1. Check your account's audit logs (https://github.com/settings/security-log?q=action%3Arepo.create) to see if a repo containing s1ngularity-repository in the name was published to your Github account. If so your credentials were likely compromised. Unfortunately, Github may have proactively deleted the repo for you. To be safe, rotate any credentials such as Github, NPM, and anything that may have been in your environment variables.
2. Check your local machine to see if there is a file at `/tmp/inventory.txt`, this file will contain a list of files which the malware probably read from. If this file exists, you have been affected.
3. Check this https://github.com/[GithubSlug]?tab=repositories&amp;q=s1ngularity-repository to see if you have a repo containing s1ngularity-repository remains on your Github account. If you do not have the repository available to you anymore, reach out to Github support and they can provide you the contents of the repository.
4. Download the file in the repo for your own records.
5. Then, remove the repo from GitHub.
6. E-mail security@nrwl.io and we will instruct you on how to decode the file so you…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cxm3-wv7p-598c"/>
  </entry>
</feed>
