GitHub Discloses 3,800 Internal Repositories Exfiltrated via TeamPCP Supply Chain Attack on Nx Console VS Code Extension
The Hacker News / Help Net Security·high signal
A trojanized Nx Console VS Code extension (v18.95.0, 2.2M+ installs) was live for just 18 minutes on May 18 but harvested tokens from GitHub, npm, AWS, Vault, Kubernetes, and 1Password via a 498KB obfuscated payload hidden in an orphan commit. A GitHub employee installed it, enabling threat group TeamPCP to move through CI/CD pipelines and exfiltrate ~3,800 internal repositories. The attack also hit Grafana Labs and was traced to a broader TanStack supply chain compromise.