CISA | Alerts
Follow
Supply Chain Compromises Impact Nx Console and GitHub Repositories
CISA is addressing escalating cyberattacks exploiting software supply chain vulnerabilities, focusing on CI/CD pipelines and developer ecosystems. Recent breaches showcase threat actors targeting tools within enterprise, cloud, and DevOps environments. A significant incident involved a malicious Nx Console VS Code extension, leading to GitHub repository access and data exfiltration. The compromised extension (version 18.95.0) auto-updated, potentially affecting developers with Nx Console installed. CISA assigned CVE-2026-48027 and added the compromised version to its KEV Catalog.The "Megalodon" campaign injected malicious GitHub Action workflows to steal CI/CD secrets and credentials. CISA recommends monitoring workflow activity and reverting suspicious changes by automated accounts. Organizations should conduct forensic reviews if compromised and rotate secrets like API keys and cloud credentials. CISA suggests delaying package downloads for three hours and pinning software to trusted versions. Pulling packages only from trusted sources is critical for security. Several resources are available for detailed information on these compromises. CISA provides this information for informational purposes only and does not endorse any specific products or services.