Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3486 articles · 157946 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITEDPATCHED
github · nx console visual studio code extension

Supply Chain Compromise via Malicious Nx Console Visual Studio Code Extension v18.95.0

72% confidence

Description

A maliciously modified version of the Nx Console Visual Studio Code extension (version 18.95.0) was used to facilitate unauthorized access to GitHub internal systems, resulting in exfiltration of approximately 3,800 internal repositories containing proprietary source code and internal configuration data.

Affected Products

VendorProductVersions
githubnx console visual studio code extension18.95.0

Related News (1 articles)

Tier B
CCCS Canada1d ago
AL26-013 Security incident impacting GitHub internal repositories
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
18.96.0
CWECWE-494
PublishedMay 29, 2026
Last enriched1d ago
Tags
supply chaincode repositoryexfiltrationmalicious extensionvisual studio code
Trending Score34
Source articles1
Independent1
Info Completeness9/14
Missing: cve_id, cvss, epss, kev, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-8606
Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint
Trending: 27
MEDIUMCVE-2026-44837EXP
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
Trending: 27
MEDIUMCVE-2026-44836EXP
view_component: Preview Route Can Dispatch Inherited Helper Methods
Trending: 27
NONECVE-2026-9312
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to internal services via path traversal in upload endpoint
Trending: 23
LOWCVE-2026-45803EXP
gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Trending: 14

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
May 29, 2026
Discovered by ZDM
May 29, 2026
Actively Exploited
May 29, 2026
Exploit Available
May 29, 2026
Patch Available
May 29, 2026