top of page
perceptive_background_267k.jpg

Supply Chain Compromises Impact Nx Console and GitHub Repositories

Published:

28 mei 2026 om 12:00:00

Alert date:

28 mei 2026 om 20:05:25

Source:

cisa.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Enterprise Applications

CISA reports multiple supply chain attacks targeting developer ecosystems and CI/CD pipelines. Threat actors compromised Nx developer systems and used a malicious Nx Console VS Code extension (version 18.95.0) to compromise a GitHub employee's device, leading to unauthorized access and data exfiltration from internal GitHub repositories. A separate campaign called 'Megalodon' involved injecting malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens from public repositories. The malicious extension was distributed through VS Code's automatic update mechanism, affecting systems without manual intervention. CVE-2026-48027 has been assigned and added to CISA's Known Exploited Vulnerabilities Catalog.

Technical details

Mitigation steps:

Affected products:

Nx Console
GitHub
Visual Studio Code

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page