logo

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

ID: 1f279aab-ec78-5118-9fac-4fb45ca1214a

STIX ID: report--1f279aab-ec78-5118-9fac-4fb45ca1214a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: [email protected] (The Hacker News)

...
...

GitHub confirmed a supply-chain compromise where a trojanized Nx Console (nrwl.angular-console) VS Code extension—attributed to the cybercriminal group TeamPCP—was used to distribute a credential-stealer that harvested secrets (1Password, npm, GitHub, AWS, Anthropic) and enabled exfiltration of roughly 3,800 internal GitHub repositories; the malicious extension was live for only 18 minutes but was sufficient to compromise developer systems and highlights systemic risks in auto-update and developer-tool distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.