GitHub links the breach of 3,800 internal repositories to the TanStack npm supply-chain attack, saying hackers used a malicious Nx Console VS Code extension
GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the NxConsole VS Code extension …
BleepingComputerSergiu Gatlan
Context & Ripple Effects
This report follows GitHub’s confirmation that roughly 3,800 internal repositories were breached after an employee installed a malicious VS Code extension. The new attribution connects that incident to the TanStack npm supply-chain attack and identifies Nx Console as the initial access path.
It also extends a recurring GitHub security arc: prior incidents involved stolen OAuth tokens from third-party developer services, while the related May coverage describes malware spreading through automated commits across thousands of repositories. The common exposure point is the developer toolchain around the code host, not just the code host itself.
First-order effects
GitHub’s internal-repository breach is now tied to a specific supply-chain campaign and an extension-based entry point, narrowing the scope of incident response around the affected extension, accounts, and repositories.
Nx Console and the TanStack-related ecosystem face immediate scrutiny from users and maintainers because a developer-tool installation was used to reach GitHub’s internal environment.
Second-order effects
Organizations using VS Code extensions alongside npm dependencies will have stronger reason to review extension provenance, permissions, and links between local developer tools and source-control credentials.
The linkage between a package-registry attack and a code-host breach increases pressure on repository and package-platform operators to detect malicious commits and compromised developer identities as connected events rather than isolated incidents.
Third-order effects
If attacks continue to bridge extensions, package ecosystems, automated commits, and repository access, software-supply-chain defense will shift further toward controlling trusted developer-tool paths rather than focusing mainly on dependency scanning.
The pattern could make ecosystem trust increasingly dependent on tighter verification of extensions and automated repository actions; the available coverage does not establish which controls GitHub or other platforms will adopt.
The trend: This is one data point in the broadening of software-supply-chain attacks from compromised packages into the developer tools and repository workflows that distribute and maintain code.
We're continuing to work with Microsoft and GitHub to investigate the impact of the malicious Nx Console version 18.95.0. I'll share any updates on X (@jeffbcross and @NxDevTools) as well as in our security advisory: https://github.com/.... Initially, Microsoft indicated to us
Github hack was via this extension nrwl.angular-console VSIX Starting to get detected by more than just VT now https://www.virustotal.com/... https://opensourcemalware.com/ ...
SECURITY ADVISORY: A malicious version of Nx Console v18.95.0 was published today at 2:36 PM CEST and was available for 11 minutes, until 2:47 PM CEST, when we patched the issue. Nx Console v18.100.0 is the latest safe version to use. More info: https://github.com/...
The Nx team is being transparent. Genuinely. But “28 installs per Microsoft” vs “6000 activations per our analytics” is a hell of a gap for one supply-chain weekend. If download stats are that wrong for a 2.2M-install extension — what else are we undercounting in the npm and
@akses_0x00 @NxDevTools We published the detailed security advisory on GitHub and posted about it on X and Discord immediately after patching on Monday. I'm actually still waiting for confirmation from GitHub that Nx Console was the unnamed VSC extension in their postmortem, but …
Looks like this is the extension that popped GitHub. So the hackers used the same MO as npm worm - but instead of a wormy boy - they pushed a malicious VS Code extension out. Nx Console says they see evidence of ~6k downloads of the malware.
The Nx Dev Tools CEO confirms that his company's Nx Console VS Code extension served as the initial entry point for the GitHub repo hack: https://x.com/... Nx incident: https://github.com/... Step Security report: https://www.stepsecurity.io/ ...
NEW: This week's GitHub breach is just the latest in a string of at least 20 software supply chain attacks carried out by the hacker group TeamPCP. @agreenberg.bsky.social and @lhn.bsky.social report: www.wired.com/story/teampc...
2026 is awesome. '"We are here today to advertise GitHub's source code and internal orgs for sale," TeamPCP wrote on BreachForums... “Everything for the main platform is there..."' new from @agreenberg.bsky.social & @lhn.bsky.social in @wired.com www.wired.com/story/teampc... @g…