GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

2026-05-21T07:24:10Zdee6cade349885bfce5fbddb355afc482d03ac4e0ef14261e468ad6b98a43ffa
CVE-2026-31635CVE-2026-45585CVE-2026-9082RCEbitlockerci-cd-credentialscredential-stealerdrupalechocreep-graphworm','oauth-phishing','eviltokens','ad-fraud','tfox-tempestgithub-actionsgithub-breachgrafanalinux-kernelmalware-signing-as-a-servicenpmnx-consoleprivilege-escalationseppmailsupply-chaintanstackteamPCPvscode-extensionwebwormyellowkey

What happened

A wave of high-impact supply-chain and post-exploitation incidents was reported: GitHub confirmed internal repository exfiltration tied to a compromised developer device and a poisoned Nx Console (rwl.angular-console v18.95.0) VS Code extension that deployed a credential stealer (TeamPCP linked). Multiple software supply-chain compromises were disclosed (npm packages, TanStack affecting Grafana, a hijacked GitHub Action) alongside broad attacks on developer workstations and CI/CD secrets. Several active and disclosed vulnerabilities and PoCs increase risk: Drupal Core RCE (CVE-2026-9082), a Po

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
dee6cade349885bfce5fbddb355afc482d03ac4e0ef14261e468ad6b98a43ffa
Enrichment time
2026-05-21T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.