edge.prnewswire.com GitHub Breach Linked to Compromised Nx Console Extension
Article Content
- •The GitHub breach was caused by a compromised version of the Nx Console extension.
- •Approximately 3,800 internal repositories were affected by the attack.
- •The Mini Shai-Hulud worm utilized legitimate workflows to propagate without detection.
On May 19, 2026, GitHub announced an investigation into unauthorized access to internal repositories after a malicious Visual Studio Code extension was executed on an employee's device. The attack, attributed to the Mini Shai-Hulud worm by TeamPCP, exploited a compromised version of the Nx Console extension, version 18.95.0, published on May 18, 2026. This version contained obfuscated JavaScript that created backdoors and allowed attackers to steal GitHub credentials. The breach affected approximately 3,800 internal repositories. GitHub's response included removing the malicious extension from the Visual Studio Marketplace within 18 minutes of detection. The attack utilized legitimate workflows and trusted credentials, making detection challenging. The compromised extension was linked to a broader supply chain attack involving multiple software publishers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track TeamPCP, Mini Shai-Hulud and Nx in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Re-enabled Malicious GitHub Actions Expose Thousands to Mini Shai-Hulud Payload On September 16, 2026, two compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-, were re-enabled, exposing thousands of downstream repositories to malicious code from the May 2026 Mini Shai-Hulud campaign. The malicious tags remained intact, allowing workflows referencing these actions…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…