news.mlab.sh
Back to the feed
supply-chain

Supply Chain Compromises Impact Nx Console and GitHub Repositories

High
Summary

CISA is responding to multiple supply chain attacks targeting developer ecosystems, specifically CI/CD pipelines. A malicious Nx Console VS Code extension compromised a GitHub employee, leading to data exfiltration, and a separate campaign, dubbed “Megalodon,” injected malware into GitHub Action workflows to steal secrets. Organizations are urged to implement monitoring and remediation steps to mitigate these risks.

Recent incidents highlight the vulnerability of CI/CD pipelines to supply chain attacks. The compromise began with a malicious Nx Console VS Code extension distributed through VS Code’s automatic update mechanism, gaining access to a GitHub employee’s device and subsequently, internal repositories. This attack leveraged a prior compromise of Nx developer systems, demonstrating the potential for attackers to exploit vulnerabilities within trusted software components. The incident was formally recognized with the assignment of CVE-2026-48027 and inclusion in CISA’s KEV Catalog.

Read the full article at CISA Advisories