GitHub Internal Repos Hit by Malicious Nx Console
GitHub has confirmed a breach of its internal repositories, caused by a compromised employee device due to a malicious version of the Nx Console Visual Studio Code extension. This breach marks a significant cybersecurity incident, raising concerns about the security protocols of widely-used platforms. The issue arose when unauthorized actors gained access to a developer’s system within the Nx team, leading to the nrwl.angular-console extension being compromised.
GitHub users and developers are urged to remain vigilant in their cybersecurity practices, particularly when dealing with extensions and plugins. The breach of the GitHub internal repos highlights the need for enhanced security measures and constant monitoring of third-party tools used in software development.
As the investigation unfolds, GitHub and the Nx team emphasize their commitment to protecting users and reinforcing security measures. Developers are encouraged to verify their tools’ integrity regularly to prevent future breaches.
For a comprehensive overview of the incident, read the full report at the following link:
https://thehackernews.com/2026/05/github-internal-repositories-breached.html
