logo

GitHub breached via a malicious VS Code extension: why developer devices are the real target

ID: 239cd864-dc11-5a38-af78-191db21da90c

STIX ID: report--239cd864-dc11-5a38-af78-191db21da90c

Feed Name: Aikido Security's Blog

Threat Score
82/100

Date Published: 2026-05-20

Date Updated: 2026-07-24

...
...

A malicious update to the widely used Nx Console VS Code extension (2.2M installs) was briefly backdoored to silently collect credentials and environment files; GitHub confirmed the breach stemmed from this extension and TeamPCP claims data extraction from ~4,000 private repositories. The report highlights how trusted tooling and marketplaces are being weaponized, how traditional EDR can miss interpreted-text payloads, and advocates on-device protections (blocking flagged packages and enforcing a minimum age policy) to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.