GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
2026-05-21T07:24:10Z•dee6cade349885bfce5fbddb355afc482d03ac4e0ef14261e468ad6b98a43ffa
CVE-2026-31635CVE-2026-45585CVE-2026-9082RCEbitlockerci-cd-credentialscredential-stealerdrupalechocreep-graphworm','oauth-phishing','eviltokens','ad-fraud','tfox-tempestgithub-actionsgithub-breachgrafanalinux-kernelmalware-signing-as-a-servicenpmnx-consoleprivilege-escalationseppmailsupply-chaintanstackteamPCPvscode-extensionwebwormyellowkey
What happened
A wave of high-impact supply-chain and post-exploitation incidents was reported: GitHub confirmed internal repository exfiltration tied to a compromised developer device and a poisoned Nx Console (rwl.angular-console v18.95.0) VS Code extension that deployed a credential stealer (TeamPCP linked). Multiple software supply-chain compromises were disclosed (npm packages, TanStack affecting Grafana, a hijacked GitHub Action) alongside broad attacks on developer workstations and CI/CD secrets. Several active and disclosed vulnerabilities and PoCs increase risk: Drupal Core RCE (CVE-2026-9082), a Po
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- dee6cade349885bfce5fbddb355afc482d03ac4e0ef14261e468ad6b98a43ffa
- Enrichment time
- 2026-05-21T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.