INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Supply Chain Compromises Impact Nx Console and GitHub Repos

| 2026-05-21 14:45 HIGH HIGH
Executive Summary AI-generated
The recent incidents of malicious software compromise and unauthorized access to GitHub repositories via a poisoned third-party VS Code extension have exposed vulnerabilities in enterprise, cloud, and DevOps environments. These threats exploit tools like Nx Console that support CI/CD pipelines, code extensions, and workflows, demonstrating the sophistication of cyber threat actors who are leveraging these compromised systems for their own malicious purposes. The malicious actions carried out by these attackers include injecting malicious GitHub Action workflows to harvest sensitive data from public repositories, highlighting the need for robust security measures in software supply chain management. As a result, CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems and urging organizations to conduct forensics reviews of CI/CD logs, cloud audit trails, and affected developer machines.
Technical Mitigations AI-generated
• Implement secure workflow auditing and monitoring: Regularly audit CI/CD pipeline files, contributor activity, and direct commits to detect suspicious changes. Use tools like GitHub's "Security Advisory" feature or third-party security solutions to monitor for potential compromises. • Use pinning mechanisms with package repositories: Pin software versions in package repos to specific trusted versions to prevent malicious packages from being pulled during the build process. This can be achieved by using tools like `docker tag` and `docker pull` with pinned tags, or by manually pinning software versions in your CI/CD pipelines. • Implement three-hour waiting period before pulling new packages: When downloading new packages, wait at least three hours to ensure that any malicious or unscreened packages have been identified and removed from the community. This can be achieved through tools like `docker pull` with a pinned tag or by manually pinning software versions in your CI/CD pipelines. • Use secure VS Code extensions: Regularly update and use trusted, verified VS Code extensions to minimize the risk of compromising your system. Use extension managers like Microsoft's Extension Manager or third-party extension repositories that have been vetted for security. • Implement cloud audit trails and API key rotation: Monitor cloud audit trails and rotate/revoke all secrets accessible to CI/CD pipelines, including API keys, cloud provider credentials (e.g., AWS, Google Cloud Platform), SSH keys, Docker/npm/PyPI/Vault/Terraform/Kubernetes tokens, GitHub/GitLab/Bitbucket tokens, and developer or pipeline secrets.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud CVE-2026-48027CVE-2026-48027
Target & Sectors
CI
Incident Timeline
‎May 18
Threat actors used a malicious version of Vx Console to upload an unauthorized copy of the 18.95.0 software update to Visual Studio Marketplace on May 18.
infrastructure Visual Studio Code
infrastructure 18.95.0
organisation Cross
organisation Visual Studio Marketplace
‎May 18, 2026
Threat actors used a malicious 'Nx Console' VS Code extension to target automated accounts.
‎May 19
Threat actors used a malicious 'Nx Console' VS Code extension to gain unauthorized access.
infrastructure Vs Code
organisation Microsoft
general_metric 3800 internal repositories
‎19 May
GitHub removed the malicious VS Code extension version and isolated its endpoint following an incident.
‎2026/05/20
Threat actors used the 'Nx Console' VS Code extension to target GitHub.
‎2026/05/21
The malicious 'Nx Console' VS Code extension was distributed through the automatic update mechanism of Visual Studio Marketplace, allowing systems with installed Nx Console to receive a compromised build without manual installation action.
infrastructure Vs Code
organisation GitHub Breach Traced
infrastructure Visual Studio Code
organisation GitHub
organisation Microsoft Visual Studio Code
organisation DevOps
organisation CI
infrastructure 18.95.0
organisation Vault
organisation Kubernetes
organisation AWS IAM
organisation ECS
organisation CLI
organisation Filesystem
organisation GCP/Docker
organisation the Visual Studio Marketplace
infrastructure 2.2 installs
organisation UTC
organisation TanStackn
organisation the Mini
organisation TanStack
organisation SSH
organisation Rotate
organisation API
organisation Microsoft Azure
organisation PyPI/Vault/Terraform/Kubernetes
organisation GitHub/GitLab/Bitbucket
organisation Team PCP Allegedly Selling GitHub Repos
organisation Lapsus$
financial $50,000 group
organisation Supply Chain Compromises Impact Nx Console
organisation GitHub Repositories
organisation Megalodon
organisation GitHub Action
organisation Notify
Tactical Metrics
Metrics
infrastructure
‎Vs Code
Affected Product
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Metrics
infrastructure
‎18.95.0
Software Version
Metrics
infrastructure
2,200,000
Installs
Metrics
financial
50,000
Group
Intelligence Sources