CISA Warns Nx Console and GitHub Repositories Abused in Multiple Supply Chain Compromises – Tools Across Enterprise, Cloud and DevOps Environments Exploited


  • CISA issued a warning about ongoing supply chain attacks exploiting GitHub repos via a malicious Nx Console VSCode extension and the Megalodon campaign
  • Threat actors stole CI/CD secrets, cloud credentials and tokens by poisoning workflows, prompting CISA to call for audit of contributor activity and workflow files
  • Recommended remedies include forensic reviews, rotating/revoking all pipeline secrets, pinning trusted package versions, and delaying pulls to allow community detection

The US Cybersecurity and Infrastructure Security Agency (CISA) is warning of several ongoing supply chain attacks and is urging developers and open source platform users to apply restrictions and secure their environments.

In a news alert published earlier this week, the agency warned of attacks on GitHub repos via a malicious Nx Console Visual Studio Code (VSCode) extension, as well as the Megalodon supply chain campaign. It said these attacks show “how cyber threat actors are abusing tools and processes that support enterprise, cloud and DevOps environments – specifically CI/CD pipelines, code extensions and workflows.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top