GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
ID: 1f279aab-ec78-5118-9fac-4fb45ca1214a
STIX ID: report--1f279aab-ec78-5118-9fac-4fb45ca1214a
Feed Name: The Hacker News
GitHub confirmed a supply-chain compromise where a trojanized Nx Console (nrwl.angular-console) VS Code extension—attributed to the cybercriminal group TeamPCP—was used to distribute a credential-stealer that harvested secrets (1Password, npm, GitHub, AWS, Anthropic) and enabled exfiltration of roughly 3,800 internal GitHub repositories; the malicious extension was live for only 18 minutes but was sufficient to compromise developer systems and highlights systemic risks in auto-update and developer-tool distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
