Trusted Dev Tools Abused to Steal Code and Secrets
ID: 9c2b3190-bd3b-576a-a262-538e36438714
STIX ID: report--9c2b3190-bd3b-576a-a262-538e36438714
Feed Name: GBHackers
Adversaries are weaponizing developer tooling and CI/CD ecosystems through two active campaigns: a supply-chain compromise of the Nx Console VS Code extension (malicious update 18.95.0) resulting in a GitHub employee device compromise and source-code exfiltration (CVE-2026-48027), and the “Megalodon” campaign that injects or modifies GitHub Actions workflows to harvest API keys, cloud credentials, and tokens from automated pipelines; CISA and security firms recommend forensic reviews, secret rotation, dependency pinning, and stricter pipeline controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
