GitHub says it traces the breach of its internal repositories to the compromise of an employee device after a malicious version of the “Nx Console” Visual Studio Code extension was installed. According to GitHub, the attack begins with the poisoning of an Nx Console extension associated with the “nrwl.angular-console” package. The Nx team also reports that the extension is breached following the hacking of one of its developers’ systems.
Multiple reports describe the mechanism as follows: an attacker compromises an Nx developer account or device and then uses that access to publish or distribute a malicious extension through the VS Code marketplace, impersonating legitimate maintainers. Once users install the poisoned extension, the attacker gains a pathway to reach or execute within affected environments.
While both outlets focus on the same extension and compromise chain, they describe the situation as a supply-chain incident in which the initial foothold is the hacked developer system and the downstream impact is the compromise of devices that used the extension, including a GitHub employee device. GitHub and the Nx team frame the incident as the identified cause of the internal repository breach.