GitHub says the threat actors behind a breach of about 3,800 internal repositories gained access through a malicious version of the Nx Console VS Code extension. In statements reported by multiple outlets, GitHub’s chief information security officer identifies the attack as originating from the prior TanStack npm supply-chain compromise that affected developer tooling. The malicious extension—disguised as a legitimate, widely used tool—was installed by developers and used to steal secrets and developer credentials. Those credentials are then described as enabling the attackers to move through continuous integration and continuous deployment workflows and exfiltrate code from GitHub’s private repositories. Reports also note that the Nx Console extension has millions of installs, highlighting its potential reach. The same supply-chain-related root cause has been cited in connection with other incidents, including Grafana Labs, though the extent and details of each victim environment are not fully consistent across reporting. Overall, the accounts converge on a chain in which a compromised developer extension derived from the TanStack npm event leads to credential theft, pipeline access, and subsequent repository data exposure.