/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

GitHub links the breach of 3,800 internal repositories to the TanStack npm supply-chain attack, saying hackers used a malicious Nx Console VS Code extension

what else are we undercounting in the npm andDaniel Lockyer /@daniellockyer:Nooooo pleaseeeee Daily security incidents across the entire tech world right now 🫠Jeff Cross /@jeffbcross:@akses_0x00 @NxDevTools We published the detailed security advisory on GitHub and posted about it on X and Discord immediately after patching on Monday. I'm actually still waiting for confirmation from GitHub that Nx Console was the unnamed VSC extension in their postmortem, but I assume it is. InMatt Johansen /@mat

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This follows GitHub’s confirmation that an employee-installed malicious VS Code extension led to access to roughly 3,800 internal repositories. The newer attribution connects that access path to the TanStack npm supply-chain attack and identifies Nx Console as the extension involved.

The incident sits alongside earlier npm package compromise and GitHub repository-access cases in the related coverage, showing that developer tooling, package ecosystems, and source-code access can form a connected attack surface rather than separate security domains.

First-order effects

  • GitHub, Nx, and organizations using the affected development tooling must treat the extension and the linked npm-package campaign as a shared incident path, prioritizing extension removal, credential review, and repository-access investigation.
  • The attribution gives developers and security teams a concrete artifact to assess—Nx Console—rather than an unspecified malicious VS Code extension.

Second-order effects

  • Organizations that rely on VS Code extensions and npm dependencies are likely to tighten approval and monitoring of developer-installed tooling, especially where it can access source repositories or build environments.
  • Extension publishers and package maintainers face greater pressure to communicate patches and advisories quickly, because compromise in one developer-tool channel can create downstream trust issues for adjacent packages and projects.

Third-order effects

  • If similar incidents continue, software-supply-chain security will increasingly need to cover the full developer workstation path—editor extensions, identity tokens, repositories, and package publication—not only dependency scanning.
  • The pattern may accelerate a shift from broad trust in ecosystem tooling toward more controlled extension distribution, least-privilege repository access, and stronger provenance expectations; the corpus does not establish which controls will become standard.

The trend: This is one data point in the convergence of IDE-extension compromise, package supply-chain abuse, and repository access into a single developer-tooling security problem.

Discussion

  • @jeffbcross Jeff Cross on x
    We're continuing to work with Microsoft and GitHub to investigate the impact of the malicious Nx Console version 18.95.0. I'll share any updates on X (@jeffbcross and @NxDevTools) as well as in our security advisory: https://github.com/.... Initially, Microsoft indicated to us
  • @akses_0x00 @akses_0x00 on x
    Github hack was via this extension nrwl.angular-console VSIX Starting to get detected by more than just VT now https://www.virustotal.com/... https://opensourcemalware.com/ ...
  • @nxdevtools @nxdevtools on x
    SECURITY ADVISORY: A malicious version of Nx Console v18.95.0 was published today at 2:36 PM CEST and was available for 11 minutes, until 2:47 PM CEST, when we patched the issue. Nx Console v18.100.0 is the latest safe version to use. More info: https://github.com/...
  • @dartilesm Diego Artiles on x
    The Nx team is being transparent. Genuinely. But “28 installs per Microsoft” vs “6000 activations per our analytics” is a hell of a gap for one supply-chain weekend. If download stats are that wrong for a 2.2M-install extension — what else are we undercounting in the npm and
  • @daniellockyer Daniel Lockyer on x
    Nooooo pleaseeeee Daily security incidents across the entire tech world right now 🫠
  • @jeffbcross Jeff Cross on x
    @akses_0x00 @NxDevTools We published the detailed security advisory on GitHub and posted about it on X and Discord immediately after patching on Monday. I'm actually still waiting for confirmation from GitHub that Nx Console was the unnamed VSC extension in their postmortem, but …
  • @mattjay Matt Johansen on x
    Looks like this is the extension that popped GitHub. So the hackers used the same MO as npm worm - but instead of a wormy boy - they pushed a malicious VS Code extension out. Nx Console says they see evidence of ~6k downloads of the malware.
  • @vxunderground @vxunderground on x
    [image]
  • @sigkitten @sigkitten on x
    this garbage tool got compromised AGAIN
  • @andyjabbour Andy Jabbour on bluesky
    2026 is awesome.  '"We are here today to advertise GitHub's source code and internal orgs for sale," TeamPCP wrote on BreachForums... “Everything for the main platform is there..."' new from @agreenberg.bsky.social & @lhn.bsky.social in @wired.com www.wired.com/story/teampc... @g…
  • @stephenturner.us Stephen Turner on bluesky
    A VS Code extension waltzes into GitHub and runs out with 3,800 internal repositories. github.blog/security/inv...  [embedded post]
  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    The Nx Dev Tools CEO confirms that his company's Nx Console VS Code extension served as the initial entry point for the GitHub repo hack: https://x.com/...  Nx incident: https://github.com/...  Step Security report: https://www.stepsecurity.io/ ...
  • r/technology r on reddit
    A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
  • r/pwnhub r on reddit
    A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
  • r/cybersecurity r on reddit
    GitHub links repo breach to TanStack npm supply-chain attack