The Nx Console Supply-Chain Attack: How a Trusted VS Code Extension Became a Credential Stealer
The Nx Console Supply-Chain Attack: How a Trusted VS Code Extension Became a Credential Stealer In May 2026, the developer ecosystem witnessed another major supply-chain security incident — this time involving the widely used Nx Console extension for Visual Studio Code. What initially looked like a routine extension update rapidly evolved into a high-impact compromise that exposed the growing fragility of modern software trust chains. The malicious release, published as Nx Console version 18.95.0 , transformed a trusted development tool into a credential-harvesting platform capable of stealing GitHub tokens, cloud credentials, SSH keys, and secrets from developer machines. The incident did not only affect individual developers; it also became linked to a broader chain of compromises involving GitHub internal repositories and the earlier TanStack npm ecosystem attack. ( Nx ) What Happened? On May 18, 2026, attackers successfully published a poisoned version of the Nx Console VS Co...