Poisoned Developer Tools Open Repo-Scale Credential Theft

A compromised developer tool can become a credential-stealing path into your repos and cloud accounts. Once an extension or workflow is trusted inside normal development and CI/CD work, attackers can use that trust to reach far beyond one workstation. CISA tied two campaigns to that pattern: the Megalodon wave injected malicious GitHub Actions into more than 5,500 open-source repositories, and a poisoned Nx Console 18.95.0 VS Code extension was used against a GitHub employee. Weak branch protection made the repo-injection campaign easier, and the result was theft of cloud credentials, API tokens, SSH keys, and other secrets. The risk does not stop at cleaning up the original extension or workflow. Stolen secrets and tokens can keep giving access after the visible compromise is removed, which turns a developer-supply-chain event into lingering control over repos and cloud services.

Part of the PlainSec briefing for 2026-05-30

Sources