VS Code extension attack compromises GitHub, OpenAI, and Mistral AI

notebookcheck.net

A VS Code extension supply chain attack compromised GitHub, OpenAI, and Mistral AI, exposing thousands of internal repositories and developer credentials. The breach originated from a poisoned Nx Console extension, itself a victim of the TanStack npm attack. Threat actor TeamPCP used harvested credentials to access internal repositories. The malicious extension was active for 18 minutes on May 18, 2026, targeting developer credentials for various services. No customer data outside internal repositories is believed to be affected at GitHub.


With a significance score of 3.5, this news ranks in the top 7.5% of today's 29985 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: