Quick Facts
- CISA added compromised Nx Console extension and GitHub vulnerabilities to Known Exploited Vulnerabilities catalog with June 10, 2026 fix deadline
- TeamPCP group’s Megalodon campaign compromised 5,561 GitHub repositories in six hours, stealing 500,000 credentials and 300GB of data
- Malicious Nx Console extension was available for 18-36 minutes but may have affected over 6,000 users according to internal analytics
The U.S. Cybersecurity and Infrastructure Security Agency added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog on May 27, 2026, following multiple supply chain attacks targeting developer tools and GitHub repositories.
The attacks center on a compromised Nx Console Visual Studio Code extension and the TeamPCP cybercrime group’s “Megalodon” campaign. Federal agencies must apply fixes by June 10, 2026.
Nx Console Breach Details
A malicious version of Nx Console 18.95.0 was published to the Visual Studio Marketplace at 12:30 PM UTC and removed 18 minutes later. The compromised extension remained available on OpenVSX for 36 minutes.
Microsoft and OpenVSX reported low download numbers of 28 and 41 respectively. However, internal analytics suggest over 6,000 users may have been affected.
The compromise led to unauthorized access to internal GitHub repositories. GitHub CISO Alexis Wales said the company has “no evidence of impact to customer information stored outside of GitHub’s internal repositories.”
Megalodon Campaign Scale
On May 18, 2026, the automated Megalodon campaign pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attacks used throwaway accounts with bot-like names including “build-bot” and “ci-bot.”
The campaign injected GitHub Actions workflows containing base64-encoded payloads that steal CI secrets, cloud credentials, SSH keys, and source code. Over 1,000 SaaS environments were impacted with 500,000 credentials stolen and 300GB of data exfiltrated.
TeamPCP, described by a spokesperson as “a loose-knit group of teenagers and young adults who couldn’t find paying work,” has partnered with LAPSUS$ to sell GitHub repositories for $95,000.
Enterprise Impact
The attacks demonstrate how threat actors target CI/CD pipelines and developer tools. Organizations using GitHub Actions workflows that store cloud credentials face potential credential theft if dependency repositories in their supply chain were compromised.
Security researcher Assaf Morag noted TeamPCP’s strength comes from “large-scale automation and integration of well-known attack techniques” rather than novel exploits.
The average cost of data breaches has reached $4.88 million globally, representing a 10% year-over-year increase. Supply chain attacks pose particular risks because they can affect multiple organizations through shared dependencies.
Read more: CISA warns that Nx Console and GitHub repositories abused in multiple supply chain compromises
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
