CISA Warns Nx Console and GitHub Repositories Abused in Multiple Supply Chain Compromises – Tools Across Enterprise, Cloud and DevOps Environments Exploited
CISA issued a warning about ongoing supply chain attacks exploiting GitHub repos via a malicious Nx Console VSCode extension and the Megalodon campaign Threat actors stole CI/CD secrets, cloud credentials and tokens by poisoning workflows, prompting CISA to call for audit of contributor activity and workflow files Recommended remedies include forensic reviews, rotating/revoking all pipeline […]









