GitHub says the threat actors behind a breach of about 3,800 internal repositories gained access through a malicious version of the Nx Console VS Code extension. In statements reported by multiple outlets, GitHub’s chief information security officer identifies the attack as originating from the prior TanStack npm supply-chain compromise that affected developer tooling. The malicious extension—disguised as a legitimate, widely used tool—was installed by developers and used to steal secrets and developer credentials. Those credentials are then described as enabling the attackers to move through continuous integration and continuous deployment workflows and exfiltrate code from GitHub’s private repositories. Reports also note that the Nx Console extension has millions of installs, highlighting its potential reach. The same supply-chain-related root cause has been cited in connection with other incidents, including Grafana Labs, though the extent and details of each victim environment are not fully consistent across reporting. Overall, the accounts converge on a chain in which a compromised developer extension derived from the TanStack npm event leads to credential theft, pipeline access, and subsequent repository data exposure.
GitHub breach linked to malicious Nx Console extension from TanStack supply-chain attack
GitHub says the threat actors behind a breach of about 3,800 internal repositories gained access through a malicious version of the Nx Console VS Code extension. In statements reported by multiple out...
- GitHub states hackers accessed about 3,800 internal repositories.
- GitHub traces the incident to a malicious version of the Nx Console VS Code extension.
- The malicious extension is linked to the prior TanStack npm supply-chain attack.
- The extension is reported to steal secrets and developer credentials.
- Stolen credentials are described as enabling access through CI/CD pipelines and data exfiltration.
GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. A malicious version of the otherwise benign extension was used to steal secrets and developer credentials, which were then used to move through CI/CD pipelines and exfiltrate around 3,800 of GitHub’s private code repositories. One missed token, many victims The company … More → The post GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise appeared first on Help Net Security.
3 months agoGitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week's TanStack npm supply-chain attack. [...]
3 months ago
Judge rejects Trump’s third bid to move hush-money conviction to federal court
A federal judge rejects Donald Trump’s latest effort to overturn his New York hush-money conviction by moving the case t...
Infosys Public Services CEO Lax Gopisetty unreachable after Nepal floods
Infosys Public Services CEO Lax Gopisetty is reported missing and unreachable following devastating floods in Nepal, acc...
Ryan Sieg wins first NASCAR O’Reilly Series race at Daytona
Ryan Sieg wins a NASCAR O’Reilly Auto Parts Series race at Daytona International Speedway. Multiple outlets report that...