GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension

2026-05-21T14:52:25Zf0dee7c889893f6364abc88eb00a36ca8f7cfcc9fd5e7a27988be36e057d594f
ai-securityandroid-malwareantvexchange-zero-dayfragnesiagithub-breachgremlin-stealerlinux-kernel-ptracelocal-privilege-escalationmini-shai-huludmustang-pandanpmnx-consolepremium-billing-fraudpypisbomssh-key-leaksupply-chaintanstackteampcpvs-code-extensionwebworm-apt

What happened

Infosecurity Magazine roundup highlights a major supply-chain and code‑integrity crisis: a malicious 'Nx Console' VS Code extension (published by an actor impersonating an Nx maintainer) has been linked to a breach of GitHub internal repositories (TeamPCP claim). Concurrent large-scale supply‑chain compromises include the Mini Shai‑Hulud campaign hitting AntV and TanStack npm packages (spreading to PyPI). The feed also covers multiple high‑impact vulnerabilities and malware campaigns — a nine‑year‑old Linux ptrace flaw leaking SSH keys and password hashes, the Fragnesia local privilege‑escal​​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
f0dee7c889893f6364abc88eb00a36ca8f7cfcc9fd5e7a27988be36e057d594f
Enrichment time
2026-05-21T14:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.