logo

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

ID: 493d10b3-f461-58b1-a9c8-817de7198851

STIX ID: report--493d10b3-f461-58b1-a9c8-817de7198851

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers identified a compromised Nx Console VS Code extension (rwl.angular-console v18.95.0) that silently fetched and executed an obfuscated payload from an orphan commit in the upstream repository, spawning a multi-stage credential stealer and supply-chain poisoning toolkit. The malware harvested a wide range of developer secrets (1Password, Claude/Anthropic configurations, npm/GitHub/AWS tokens), installed a macOS Python backdoor that uses the GitHub Search API as a dead-drop, and included Sigstore integration enabling issuance of provenance-signed malicious npm packages. The maintainers recommended updating to v18.100.0+, terminating suspicious processes, removing on-disk artifacts, and rotating all reachable credentials; the report also lists explicit IoCs (files, processes, and timestamps) and details numerous related malicious npm packages and campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.