MAL-2026-5162

    Dashboard / Malicious Package / MAL-2026-5162

    MAL-2026-5162

    Published: 1 Jun 2026Last Modified: 2 Jun 2026

    Summary: Malicious code in nrwl.angular-console (VSCode:https://open-vsx.org)

    Details: Source: google-open-source-security (12636eadc931d19fc68ca6d30f5397404c6b782a67537c770c944ed9337a4125) The compromised version of the Nx Console VS Code extension contains malicious code injected into its main execution file. When a developer opens a workspace, the extension triggers a background task to download and execute an obfuscated payload from a remote repository. This payload performs anti-analysis checks and runs as a daemon to collect sensitive credentials, cloud tokens, and secrets from the developer's environment. The harvested data is exfiltrated via HTTPS, GitHub APIs, and DNS tunneling. The malware also establishes persistence through a macOS LaunchAgent and a Python backdoor, using the GitHub Search API as a command and control channel. The impact of this compromise includes the potential theft of AWS, GCP, Azure, npm, SSH, and Vault secrets, leading to unauthorized access to internal repositories and infrastructure.

    Affected packages

    Package

    Name: nrwl.angular-console

    Purl:

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    18.95.0
    MAL-2026-5162 | CVE-DB