GitHub Breach Caused by Poisoned Nx Console VS Code Extension
Uninstall the poisoned nrwl.angular-console extension and replace with a verified version.
Uninstall the poisoned nrwl.angular-console extension and replace with a verified version.
Summary
GitHub confirmed that an internal repository breach was caused by a poisoned version of the Nx Console Visual Studio Code extension, nrwl.angular-console.
The compromise originated from an employee device that was infected, allowing attackers to inject malicious code into the extension. The poisoned extension was then distributed to developers, potentially exposing sensitive code and credentials. The incident underscores the risks of third‑party extensions and the importance of verifying extension sources. GitHub has advised users to uninstall the compromised extension and install a verified version from the official marketplace. The company is also conducting a thorough investigation into the breach and will provide further updates.
Key changes
- GitHub breach caused by poisoned nrwl.angular-console VS Code extension.
- Compromise originated from an infected employee device.
- Poisoned extension distributed to developers, exposing code and credentials.
- GitHub advised uninstalling the compromised extension.
- Users should install a verified version from the official marketplace.