Compromised Nx Console VS Code Extension Steals Developer and Cloud Secrets
ID: 1e99619a-cbb3-51c5-820f-ae8e8e14cf0e
STIX ID: report--1e99619a-cbb3-51c5-820f-ae8e8e14cf0e
Feed Name: GBHackers
A malicious version (v18.95.0) of the Nx Console VS Code extension was briefly published to the Visual Studio Code Marketplace and, when opened, launched a 498 KB obfuscated payload that harvests developer and cloud credentials, abuses Sigstore to forge provenance for signed npm artifacts, and installs persistent backdoors and resilient exfiltration channels; the rogue build was live for ~11 minutes but poses widespread risk due to auto‑updates and the extension's large install base, and the report includes file hashes, network indicators, behavior analysis, and recommended remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
