Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Compromised Nx Console Targets VS Code with Credential Theft

Compromised Nx Console Targets VS Code with Credential Theft

Posted on May 19, 2026 By CWS

Cybersecurity experts have identified a compromised version of the Nx Console extension for the Microsoft Visual Studio Code (VS Code) Marketplace, posing a significant threat to developers. The affected version, rwl.angular-console 18.95.0, is a widely-used interface for code editors, notably VS Code, with over 2.2 million installations. Notably, the Open VSX version remains unaffected.

Details of the Breach

The breach was uncovered by StepSecurity researcher Ashish Kurmi, who reported that as soon as developers opened any workspace, the compromised extension executed an obfuscated payload from a neglected orphan commit in the official nrwl/nx GitHub repository. This payload acts as a multi-step credential stealer, designed to extract developer secrets via various channels including HTTPS and DNS tunneling. A Python backdoor is also deployed on macOS systems, utilizing the GitHub Search API for further commands.

According to an advisory released by the extension’s maintainers, the root cause was traced back to a developer whose machine was compromised, leading to the leak of their GitHub credentials. Though details of the initial incident remain undisclosed, the credentials have been temporarily revoked to prevent further exploitation. These credentials were used to push an unsigned commit injecting the stealer malware, activated when any VS Code workspace is opened.

Implications and Mitigation Steps

The malware conducts checks to avoid infecting systems in Russian/CIS time zones and operates as a background process to collect credentials from various sources, including 1Password vaults, npm, GitHub, and AWS configurations. One notable feature of the malware is its integration with Sigstore for issuing certificates and generating provenance attestations, enabling attackers to publish npm packages that appear legitimate.

The Nx team confirmed that a small number of users were impacted by this breach. Users are urged to update to version 18.100.0 or later and have been provided with indicators of compromise, such as the presence of certain files and processes. Affected users should remove these artifacts and rotate all accessible credentials and secrets.

Ongoing Threats in the Ecosystem

This incident marks the second attack on the Nx ecosystem within a year, following a 2025 attack involving npm packages in a campaign named s1ngularity. In the latest attack, the focus shifted to the VS Code extension. Concurrently, researchers have found various malicious packages in open-source repositories, including npm packages with hidden binaries designed to steal developer credentials.

These packages range from those impersonating legitimate libraries to ones that install remote access trojans or steal session cookies. A coordinated campaign by an Indonesian-speaking threat actor involves 38 npm packages exploiting dependency confusion to deceive CI/CD pipelines, underscoring the ongoing threats faced by developers and the need for enhanced vigilance in the open-source community.

The evolving nature of these attacks highlights the critical need for developers to remain vigilant and adopt robust security practices to safeguard their development environments.

The Hacker News Tags:AWS, credential stealer, Cybersecurity, developer security, GitHub, GitHub API, Malware, NPM, npm packages, Nx Console, Open VSX, Python backdoor, Sigstore, supply chain attack, VS Code

Post navigation

Previous Post: Sensitive GovCloud Credentials Exposed on GitHub
Next Post: Massive npm Supply Chain Attack Targets Antv Packages

Related Posts

n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens The Hacker News
CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users The Hacker News
FedRAMP at Startup Speed: Lessons Learned FedRAMP at Startup Speed: Lessons Learned The Hacker News
Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims The Hacker News
Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover The Hacker News
Cisco Patches Actively Exploited SD-WAN Vulnerability Cisco Patches Actively Exploited SD-WAN Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome DevTools Enables Session Hijacking in Windows
  • Mustang Panda’s Enhanced CoolClient and Rootkit Tactics
  • Cavern Framework Evolves with New DNS and Google Apps Integration
  • Critical Flaw in Forminator Plugin Allows Remote Code Execution
  • Critical GitLab Flaw Allows Project Deletion Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome DevTools Enables Session Hijacking in Windows
  • Mustang Panda’s Enhanced CoolClient and Rootkit Tactics
  • Cavern Framework Evolves with New DNS and Google Apps Integration
  • Critical Flaw in Forminator Plugin Allows Remote Code Execution
  • Critical GitLab Flaw Allows Project Deletion Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark