CVE-2026-48027
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: nx Console is the user interface for Nx & Lerna. Known ransomware campaign use. EPSS 2% (76th percentile).
CISA federal remediation date Jun 10
Vulnerabilities & Exploits · Supply Chain
A compromised developer tool can become a credential-stealing path into your repos and cloud accounts. Once an extension or workflow is trusted inside normal development and CI/CD work, attackers can use that trust to reach far beyond one workstation.
CISA tied two campaigns to that pattern: the Megalodon wave injected malicious GitHub Actions into more than 5,500 open-source repositories, and a poisoned Nx Console 18.95.0 VS Code extension was used against a GitHub employee. Weak branch protection made the repo-injection campaign easier, and the result was theft of cloud credentials, API tokens, SSH keys, and other secrets.
The risk does not stop at cleaning up the original extension or workflow. Stolen secrets and tokens can keep giving access after the visible compromise is removed, which turns a developer-supply-chain event into lingering control over repos and cloud services.
1 source · May 29
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: nx Console is the user interface for Nx & Lerna. Known ransomware campaign use. EPSS 2% (76th percentile).
CISA federal remediation date Jun 10
Cybersecurity Dive
CISA urges security teams to check for software development compromises
The agency warned about a wave of attacks targeting credentials and other secrets across critical supply chains.
originalPart of the PlainSec briefing for 2026-05-30
Every edition of this story: Poisoned Developer Tools Open Repo-Scale Credential Theft