PHONES Huawei Leads China Smartphone Market as Apple Grows Amid 2% Decline GAMES Phasmophobia Gets Deildegast Ghost and 13 Willow Street Rework STEAM Fallout 76 Update 2.28 Released: Infestations Rebalanced and Boss Loot Fixed GAMES Former Forza Director Calls Xbox Game Pass ‘A Real Shame’ GAMES Bethesda Takes Fallout 76 Servers Offline for July 21 Title Update INTEL Kirin 9030 Pro Teardown Shows SMIC N+3 Beats Intel 18A Pitch PLAYSTATION 5 Wreckreation 2 Announced for PS5, Xbox Series, and PC NINTENDO SWITCH Dear Passengers Console Status: PS, Xbox, PC, and Switch Availability XBOX SERIES X Xbox Game Pass Adds 6 New Games in July 2026, Including Halo GAMES Xbox Game Pass Price Cuts to $22.99 as Seven New Titles Join Service GAMES Hunty Zombie July 2026 Reward Codes: Free Items for Roblox Players GAMES Dear Passengers Release News & Demo Details for 2026 Launch HANDHELD GAMING Anbernic RG SP Launches with GBA SP Design and Thinner Chassis NINTENDO SWITCH ASYLUM Console Release Brings Horror Adventure to PS5, Xbox, Switch

Nx Console VS Code Extension Breach Compromises GitHub, OpenAI

Lena Fischer 0 comments 2 min read

A trojanized Nx Console VS Code extension compromised GitHub and AI companies in May 2026. Learn how the supply chain attack exfiltrated thousands of repos.

Nx Console VS Code Extension Breach Compromises GitHub, OpenAI
SOFTWARE AND UPDATES

A security incident involving the Nx Console VS Code extension compromised major technology companies in May 2026. The attack originated from a poisoned version of the extension, which served as a vector for a broader supply chain breach. Threat actor group TeamPCP leveraged this vulnerability to infiltrate GitHub, OpenAI, and Mistral AI. The campaign targeted developer credentials and internal source code across all three organizations.

Malicious extension harvested developer credentials across major tech firms

The malicious build, identified as Nx Console 18.95.0, remained live on the Visual Studio Marketplace for exactly eighteen minutes between 12:30 pm and 12:48 pm UTC on May 18, 2026. This version carried CVE-2026-45321, a vulnerability rated at 9.6 on the CVSS scale. The trojanized extension executed a shell command disguised as a routine setup task during installation. It deployed a credential stealer that harvested tokens from password managers and cloud services.

The breach resulted in the exfiltration of approximately 3,800 internal GitHub repositories. OpenAI confirmed that two employee devices were compromised with limited credential material taken. Mistral AI reported that its npm and PyPI SDKs became trojaned as part of the same coordinated campaign. The attack spread across 170 npm packages and two PyPI packages originating from a compromise in TanStack's router ecosystem.

GitHub CISO Alexis Wales stated there is no evidence of impact to customer information stored outside of internal repositories. OpenAI described the incident as reflecting a shift toward targeting shared software dependencies rather than single companies. The exact extent of data taken from OpenAI and Mistral AI remains unclear due to limited public details on specific files or credentials.

TanStack has not confirmed additional remediation steps beyond the initial supply chain compromise. Microsoft is simultaneously addressing an unrelated unpatched vulnerability in its BitLocker encryption system.

Source: NotebookCheck

Discussion

0 comments

Leave a comment