FSR Onimusha: Way of the Sword Steam Deck Performance Guide NINTENDO SWITCH 2 Digimon Story: Time Stranger DLC ‘A Hero’s Eternal Legacy’ Announced PLAYSTATION 5 Cygames Launches Where the Seeds Fall for PS5, Switch 2, and PC PLAYSTATION 5 Dragon Ball Xenoverse 3 Trailer Reveals New Android Avatar Race PLAYSTATION 5 Uncanyon Puzzle Adventure Announced for PS5, Xbox Series, Switch 2, and PC NINTENDO Final Fantasy Resonance Demo Now Live With Save Carryover HANDHELD GAMING FunnyPlaying Retro Pixel MiniGB Brings Game Boy Cartridges to a 2.6-Inch Handheld CONSOLES LEGO PlayStation Set Ships October 4 for $180 With Opening Disc Drive NINTENDO SWITCH How To Fish Console Availability: PS5, Xbox Series X|S, and Switch DLSS NVIDIA DLSS Multi Frame Generation Mod Brings Blackwell Tech to RTX 40 Series GAMES Killing Floor 3 Update 2.017 Fixes Stuttering and Buffs Damage PC HARDWARE Acer EP130K ePaper Monitor: 13.3-inch 3.2K Display Ships in 2027 AYANEO MSI Claw 8 EX AI+ Gets $1,499 Price Cut With Arc B370 GPU GAMES GTA 6 Miami Marketing Blocked by Sheriff Over Crime Stereotypes

Nx Console VS Code Extension Breach Compromises GitHub, OpenAI

Lena Fischer 2 min read

A trojanized Nx Console VS Code extension compromised GitHub and AI companies in May 2026. Learn how the supply chain attack exfiltrated thousands of repos.

Nx Console VS Code Extension Breach Compromises GitHub, OpenAI
SOFTWARE AND UPDATES

A security incident involving the Nx Console VS Code extension compromised major technology companies in May 2026. The attack originated from a poisoned version of the extension, which served as a vector for a broader supply chain breach. Threat actor group TeamPCP leveraged this vulnerability to infiltrate GitHub, OpenAI, and Mistral AI. The campaign targeted developer credentials and internal source code across all three organizations.

Malicious extension harvested developer credentials across major tech firms

The malicious build, identified as Nx Console 18.95.0, remained live on the Visual Studio Marketplace for exactly eighteen minutes between 12:30 pm and 12:48 pm UTC on May 18, 2026. This version carried CVE-2026-45321, a vulnerability rated at 9.6 on the CVSS scale. The trojanized extension executed a shell command disguised as a routine setup task during installation. It deployed a credential stealer that harvested tokens from password managers and cloud services.

The breach resulted in the exfiltration of approximately 3,800 internal GitHub repositories. OpenAI confirmed that two employee devices were compromised with limited credential material taken. Mistral AI reported that its npm and PyPI SDKs became trojaned as part of the same coordinated campaign. The attack spread across 170 npm packages and two PyPI packages originating from a compromise in TanStack's router ecosystem.

GitHub CISO Alexis Wales stated there is no evidence of impact to customer information stored outside of internal repositories. OpenAI described the incident as reflecting a shift toward targeting shared software dependencies rather than single companies. The exact extent of data taken from OpenAI and Mistral AI remains unclear due to limited public details on specific files or credentials.

TanStack has not confirmed additional remediation steps beyond the initial supply chain compromise. Microsoft is simultaneously addressing an unrelated unpatched vulnerability in its BitLocker encryption system.

Source: NotebookCheck