Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Breach Linked to Malicious VS Code Extension

GitHub Breach Linked to Malicious VS Code Extension

Posted on May 21, 2026 By CWS

GitHub has confirmed a security breach involving its internal repositories, attributed to a compromised employee device. The breach was linked to a tainted version of the Nx Console extension for Microsoft Visual Studio Code (VS Code), highlighting the risks associated with developer tool compromises.

Details of the Breach

The breach was unveiled after the Nx team reported that their nrwl.angular-console extension was infiltrated. This incident followed the recent TanStack supply chain attack, which affected several major tech entities, including OpenAI and Grafana Labs. The attackers, known as TeamPCP, managed to extract approximately 3,800 repositories.

GitHub’s Chief Information Security Officer, Alexis Wales, assured that customer information stored outside GitHub’s internal systems remains unaffected. However, GitHub is monitoring the situation closely and has implemented measures to contain the incident, including rotating critical secrets.

Industry Response and Analysis

Narwhal Technologies, the company behind nx.dev, acknowledged the need for fundamental changes in securing developer tools and open-source distribution. Jeff Cross, co-founder of Narwhal Technologies, emphasized the necessity of re-evaluating existing security assumptions within the software ecosystem.

TeamPCP’s rapid rise in notoriety stems from their focus on large-scale software supply chain attacks, targeting popular open-source projects. In this case, the malicious VS Code extension was briefly available on the Visual Studio Marketplace, yet it sufficed to distribute a credential-stealing tool.

Implications for Developers

The compromised extension operated stealthily, executing a hidden package upon startup. This incident underscores the vulnerabilities inherent in the interconnected nature of modern software. Attackers exploit trusted tools to extract credentials, perpetuating a cycle of breaches.

Security researchers have critiqued the default auto-update feature in extension marketplaces, such as VS Code, Cursor, and others. While intended to keep software up-to-date, it inadvertently provides attackers with a mechanism to distribute malicious updates directly to users.

Moving forward, the industry is urged to implement stricter review processes and impose waiting periods for updates to mitigate risks. As the software supply chain evolves, enhanced security measures and collaboration among open-source maintainers are essential to prevent similar incidents.

The Hacker News Tags:auto-update risks, credential theft, Cybersecurity, developer tools, extension compromise, GitHub, incident response, Nx Console, open source security, security breach, Software Security, software supply chain, supply chain attack, TeamPCP, VS Code

Post navigation

Previous Post: GhostTree Technique Exploits EDR Weaknesses
Next Post: Claude Code Sandbox Flaw Risks User Data Exposure

Related Posts

Over 46,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack Over 46,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack The Hacker News
Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics The Hacker News
Google Reports Exploitation of Qualcomm Android Vulnerability Google Reports Exploitation of Qualcomm Android Vulnerability The Hacker News
New TokenBreak Attack Bypasses AI Moderation with Single-Character Text Changes New TokenBreak Attack Bypasses AI Moderation with Single-Character Text Changes The Hacker News
Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News
CarPlay Exploit, BYOVD Tactics, SQL C2 Attacks, iCloud Backdoor Demand & More CarPlay Exploit, BYOVD Tactics, SQL C2 Attacks, iCloud Backdoor Demand & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Firefox Extensions Exploit Web3 Users to Steal Wallet Data
  • Zyxel Fixes Critical Command Injection in Access Points
  • Manic Malware Targets Android Devices with Innovative Techniques
  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Firefox Extensions Exploit Web3 Users to Steal Wallet Data
  • Zyxel Fixes Critical Command Injection in Access Points
  • Manic Malware Targets Android Devices with Innovative Techniques
  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark