Vulnerabilities · 108 days ago

Poisoned Developer Tools Open Repo-Scale Credential Theft

A compromised developer tool can become a credential-stealing path into your repos and cloud accounts. Once an extension or workflow is trusted inside normal development and CI/CD work, attackers can use that trust to reach far beyond one workstation.

CISA tied two campaigns to that pattern: the Megalodon wave injected malicious GitHub Actions into more than 5,500 open-source repositories, and a poisoned Nx Console 18.95.0 VS Code extension was used against a GitHub employee. Weak branch protection made the repo-injection campaign easier, and the result was theft of cloud credentials, API tokens, SSH keys, and other secrets.

The risk does not stop at cleaning up the original extension or workflow. Stolen secrets and tokens can keep giving access after the visible compromise is removed, which turns a developer-supply-chain event into lingering control over repos and cloud services.

CVE-2026-48027

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: nx Console is the user interface for Nx & Lerna. Known ransomware campaign use. EPSS 2% (76th percentile).

CISA federal remediation date Jun 10

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-30

Editions

Related stories