logo

Trusted Dev Tools Abused to Steal Code and Secrets

ID: 9c2b3190-bd3b-576a-a262-538e36438714

STIX ID: report--9c2b3190-bd3b-576a-a262-538e36438714

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Mayura Kathir

...
...

Adversaries are weaponizing developer tooling and CI/CD ecosystems through two active campaigns: a supply-chain compromise of the Nx Console VS Code extension (malicious update 18.95.0) resulting in a GitHub employee device compromise and source-code exfiltration (CVE-2026-48027), and the “Megalodon” campaign that injects or modifies GitHub Actions workflows to harvest API keys, cloud credentials, and tokens from automated pipelines; CISA and security firms recommend forensic reviews, secret rotation, dependency pinning, and stricter pipeline controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.