OpenSSF/OSV advisory MAL-2025-41443 confirms this npm version as malicious. The nx project and associated plugins were compromised via a vulnerable GitHub workflow that allowed code injection and the theft of an NPM token.
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in nx (npm)
Details
The nx project and associated plugins were compromised via a vulnerable GitHub workflow that allowed code injection and the theft of an NPM token.
Decision reason
OpenSSF Malicious Packages via OSV confirms nx@20.12.0 as malicious (MAL-2025-41443): Malicious code in nx (npm)