I was bitten by this today - the payload dropped a Python C2 backdoor and LaunchAgent. (fortunately, it failed to run due to failed dependencies...)
Incidentally, my local install was almost 2 hours after the maintainers claim they pulled it from the marketplace so the real-world exposure window appears to have been substantially longer than 11 minutes.
`2026-05-18 16:34:11.092 [info] Extracted extension to .../nrwl.angular-console-18.95.0`
If you want further information on how the attack was obfuscated & executed, I posted in the nx-console Issues board [here](https://github.com/nrwl/nx-console/issues/3140) - (apols for the LLM-assisted post, as you would imagine I was in something of a hurry to report it)