news.mlab.sh
Back to the feed
supply-chain

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

High
Image: The Hacker News
Summary

A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was compromised, contained a multi-stage credential stealer and supply chain poisoning tool that harvested secrets from various sources, including 1Password, Anthropic Claude Code, npm, GitHub, and AWS. The attack leveraged Sigstore integration to create fraudulent provenance attestations, and coincided with the discovery of numerous other malicious npm packages targeting similar vulnerabilities.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.