Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Nx Console Extension Breach: Developer Secrets at Risk

Nx Console Extension Breach: Developer Secrets at Risk

Posted on May 19, 2026 By CWS

The Nx Console extension for Visual Studio Code, with over 2.2 million installations, was compromised in May 2026, exposing millions of developers to potential credential theft. Attackers released a malicious version of the extension that infiltrated the official VS Code Marketplace, posing serious security risks to developers.

Details of the Breach

On May 18, 2026, attackers published version 18.95.0 of the Nx Console extension using stolen credentials. This version contained a hidden payload that activated upon opening any workspace. The payload was cleverly concealed within an orphan commit on the official nrwl/nx GitHub repository.

Fortunately, the compromised version was live for only about 11 minutes before being detected and removed by the Nx team. This swift action minimized the impact, but the breach highlighted significant vulnerabilities in the supply chain.

Investigative Findings

According to a report by StepSecurity, the attack was part of a larger, multi-stage supply chain attack, marking the second incident affecting the Nx ecosystem within a year. The payload was designed to steal a wide array of credentials, targeting platforms like GitHub, npm, AWS, and more.

The sophisticated attack also included mechanisms to exfiltrate data through multiple channels, including HTTPS and DNS tunneling. This made it challenging to detect and block the data theft effectively. Additionally, it targeted AI coding assistants, a first for supply chain attacks.

Security Measures and Recommendations

Developers using the compromised version between 12:36 and 12:47 UTC on May 18 are advised to consider their credentials compromised. Immediate actions include updating to version 18.100.0 or later and removing any backdoor artifacts.

Particularly on macOS, users should remove the persistent backdoor located at ~/.local/share/kitty/cat.py and related LaunchAgent entries. It is crucial to rotate all credentials, including GitHub tokens, npm tokens, and any stored secrets, to prevent unauthorized access.

Finally, understanding the indicators of compromise, such as specific file hashes and Git commit identifiers, can aid in identifying affected systems. Developers should remain vigilant and follow best practices for securing their development environments.

Cyber Security News Tags:AI coding assistants, cloud security, credential theft, Cybersecurity, developer security, extension breach, GitHub, Malware, Nx Console, StepSecurity, supply chain attack, VS Code

Post navigation

Previous Post: Increase in Malware Attacks via MSHTA Exploitation
Next Post: Drupal Urges Immediate Core Security Updates

Related Posts

First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption Cyber Security News
CISA Added WinRaR Zero-Day (CVE-2025-8088) Vulnerability That is Actively Exploited In the Wild CISA Added WinRaR Zero-Day (CVE-2025-8088) Vulnerability That is Actively Exploited In the Wild Cyber Security News
New Phishing Attack Uses Basic Auth URLs to Trick Users and Steal Login Credentials New Phishing Attack Uses Basic Auth URLs to Trick Users and Steal Login Credentials Cyber Security News
North Korean Hackers Make History with  Billion Crypto Heist in 2025 North Korean Hackers Make History with $2 Billion Crypto Heist in 2025 Cyber Security News
New Phishing Attack Leverages Popular Brands to Harvest Login Credentials New Phishing Attack Leverages Popular Brands to Harvest Login Credentials Cyber Security News
CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyber Resilience: Key to Modern Business Continuity
  • DirtyDecrypt Exploit PoC for Linux Kernel Vulnerability Released
  • GitHub Action Hack Exposes Developer Credentials
  • Critical ChromaDB Flaw Enables Potential Server Takeover
  • Drupal Urges Immediate Core Security Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyber Resilience: Key to Modern Business Continuity
  • DirtyDecrypt Exploit PoC for Linux Kernel Vulnerability Released
  • GitHub Action Hack Exposes Developer Credentials
  • Critical ChromaDB Flaw Enables Potential Server Takeover
  • Drupal Urges Immediate Core Security Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark