logo

GitHub Internal Repositories Breached Via Weaponized VS Code Extension

ID: db0ddb57-0299-5ce1-b36b-b47e0625299b

STIX ID: report--db0ddb57-0299-5ce1-b36b-b47e0625299b

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Guru Baran

...
...

On May 18, 2026 GitHub confirmed a significant security breach after a weaponized Visual Studio Code extension (a malicious version of Nx Console) compromised an employee endpoint and resulted in exfiltration of roughly 3,800 internal repositories; GitHub removed the extension, isolated the endpoint, rotated critical secrets, and is investigating potential limited exposure of customer-derived data in some internal repositories while reporting no evidence of impact to customer-facing infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.