CVE-2026-48027 Splunk · SPL

Detect Nx Console Embedded Malicious Code Execution (CVE-2026-48027) in Splunk

CVE-2026-48027 describes an embedded malicious code vulnerability (CWE-506) in Nx Console, a popular VS Code and JetBrains IDE extension for managing Nx monorepos. A compromised or trojanized version of Nx Console contains backdoored code that executes at extension load time within the developer IDE process, enabling attacker-controlled behavior including credential harvesting, reverse shells, or supply chain lateral movement into CI/CD pipelines. This vulnerability is listed in CISA KEV, indicating active exploitation in the wild. Detection focuses on anomalous process spawning from IDE extension host processes, unexpected network connections originating from VS Code or JetBrains runtimes, and suspicious file writes consistent with embedded malicious payloads.

MITRE ATT&CK

Tactic
Initial Access Execution Persistence Command and Control

SPL Detection Query

Splunk (SPL)
spl
index=endpoint sourcetype IN ("xmlwineventlog", "crowdstrike:events:sensor", "carbon_black:edr") 
| eval parent_lower=lower(parent_process_name), proc_lower=lower(process_name), cmdline_lower=lower(process_cmdline)
| where (match(parent_lower, "(code|code-insiders|webstorm|idea|rider)") AND match(proc_lower, "(powershell|pwsh|cmd\.exe|bash|sh|python|curl|wget|certutil|mshta|wscript|cscript|nc|ncat|socat)"))
   OR match(cmdline_lower, "(nx-console|@nrwl\/nx-console|nxls|nx-language-server)")
| eval risk_score=case(
    match(proc_lower, "(powershell|pwsh|mshta|certutil)"), 90,
    match(proc_lower, "(curl|wget|nc|ncat|socat)"), 85,
    match(proc_lower, "(cmd\.exe|bash|sh)"), 60,
    true(), 40)
| table _time, host, user, parent_process_name, process_name, process_cmdline, risk_score
| sort - risk_score, _time
critical severity medium confidence

Splunk detection for Nx Console malicious embedded code (CVE-2026-48027). Correlates IDE parent processes spawning suspicious child processes or command lines referencing nx-console extension artifacts.

Data Sources

Endpoint telemetry (Crowdstrike Falcon, Carbon Black EDR, Windows Event Logs)

Required Sourcetypes

xmlwineventlogcrowdstrike:events:sensorcarbon_black:edrsyslog

False Positives & Tuning

  • Normal Nx workspace commands executed from within VS Code integrated terminal
  • Node package manager (npm/yarn/pnpm) spawned by extension for dependency resolution
  • Linter or formatter processes (ESLint, Prettier) launched by IDE extension
  • Jest or Vitest test runner child processes from Nx test targets

Other platforms for CVE-2026-48027


Testing Methodology

Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate Nx Console Extension Host Spawning Reverse Shell (Windows)

    Expected signal: DeviceProcessEvents: powershell.exe spawned with parent chain including node.exe or code.exe; DeviceNetworkEvents: TCP connect attempt to 127.0.0.1:9999

  2. Test 2Simulate Nx Console Extension Credential File Exfiltration (Linux/macOS)

    Expected signal: Process creation event: bash spawned with cat and curl in command line; Network event: HTTP POST to 127.0.0.1:8181 from bash process; File access events on .npmrc and .gitconfig

  3. Test 3Drop and Execute Malicious Script from Temp Directory (macOS)

    Expected signal: Process events: node.exe spawning sh executing a script from /tmp; File creation events for /tmp/nx_test_payload.sh and /tmp/nx_beacon.txt with initiating process node

  4. Test 4Nx Console VSIX Backdoor Package Installation Simulation

    Expected signal: File system events showing creation of extension directory and package.json under .vscode/extensions; if extension activated, bash process spawned from VS Code extension host

Unlock Pro Content

Get the full detection package for CVE-2026-48027 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections