Developer IDEs Became the Supply-Chain Entry Point

A poisoned IDE extension can turn the developer workstation into the attack path, and store vetting alone does not stop it when the extension runs trusted package commands inside normal workflows. Here, the malicious Nx Console release used that trust to pull a second stage from GitHub, then went after cloud, SSH, Vault, and Kubernetes credentials from the affected machine. TeamPCP is reported to have used a compromised GitHub employee account to publish Nx Console v18.95.0 to Visual Studio Marketplace and OpenVSX, then used the extension to reach legitimate GitHub infrastructure for the follow-on payload. The result was credential theft from a single workstation and exfiltration tied to about 3,800 internal repositories. The risk now extends beyond one bad extension. Any developer tool that can execute package-manager commands or touch source-code and cloud credentials can become the delivery path for repo theft and downstream environment access.

Part of the PlainSec briefing for 2026-07-22

Sources