news.mlab.sh
Back to the feed
threat-intel

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

High
Image: The Hacker News
Summary

GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnerability to exfiltrate approximately 3,800 repositories and steal credentials from various services including 1Password, Anthropic Claude Code, and AWS. This incident highlights the risks associated with open-source tooling and automated updates.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.