Briefing

Compromised Nx Console Extension v18.95.0 Flagged by Researchers

security
by [email protected] (The Hacker News) ·

Patch or uninstall the rwl.angular-console v18.95.0 extension immediately to stop the malicious code from running.

What to do now

Uninstall or update rwl.angular-console to a non‑compromised version immediately.

Summary

Cybersecurity researchers have flagged a compromised version of the Nx Console extension rwl.angular-console (v18.95.0) that was published to the VS Code Marketplace. The extension, which powers a UI for Angular projects, has more than 2.2 million installations across VS Code, Cursor and JetBrains. The researchers discovered malicious code that can inject scripts into the editor and potentially compromise the developer’s workspace. No official patch has been released yet, and the extension remains actively exploited. Users are advised to uninstall or update to a safe version immediately. The incident highlights the risk of third‑party extensions in the editor ecosystem.

Key changes

  • rwl.angular-console v18.95.0 flagged compromised
  • Over 2.2 million installs across VS Code, Cursor, JetBrains
  • Malicious code injects scripts into the editor
  • No official patch yet; active exploitation reported
  • Extension powers Angular UI
  • Users must uninstall or update
  • Risk of workspace compromise
  • Incident underscores third‑party extension risk

Affects

internal

Source angles · 3 perspectives

The Hacker News
Independent angle

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Open
The Hacker News
Independent angle

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

Open
Bleeping Computer
Independent angle

GitHub links repo breach to TanStack npm supply-chain attack

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting