CVE detail
CVE-2025-10894
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
Not Applicablewww.wiz.ioSep 24, 2025, 10:15 PM- https://www.stepsecurity.io/blog/supply-chain-security-alert-popular-nx-build-system-package-compromised-with-data-stealing-malwarewww.stepsecurity.io
No excerpt available.
Exploitwww.stepsecurity.ioSep 24, 2025, 10:15 PM No excerpt available.
Exploitgithub.comSep 24, 2025, 10:15 PM- https://bugzilla.redhat.com/show_bug.cgi?id=2396282bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comSep 24, 2025, 10:15 PM - https://access.redhat.com/security/supply-chain-attacks-NPM-packagesaccess.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comSep 24, 2025, 10:15 PM - https://access.redhat.com/security/cve/CVE-2025-10894access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comSep 24, 2025, 10:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-67595CVSS 9.2 · Critical
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remot…
- CVE-2026-18072CVSS 9.8 · Critical
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 1…
- CVE-2026-46412CVSS 10.0 · Critical
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker u…
- CVE-2026-46421CVSS 9.3 · Critical
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool.…
- CVE-2026-45758CVSS 9.6 · Critical
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai…
- CVE-2026-48027CVSS 9.3 · Critical
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC,…