Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
AI-summarised brief · reviewed before publication
Cybersecurity researchers flagged a compromised Nx Console extension on the VS Code Marketplace, affecting over 2.2 million installations. The compromised extension, version 18.95.0, silently fetched and executed a payload that steals developer secrets and installs a Python backdoor on macOS systems. The root cause was traced to a developer's compromised machine, which led to the push of an orphaned commit introducing the malware.
💡 Why It Matters
- · The breach enables attackers to publish malicious npm packages with valid provenance attestations, making them appear legitimate.
- · Affected users' sensitive data, including 1Password vaults and AWS secrets, are at risk of being harvested.