Find notable cyber news and cases, enriched with sources, timelines, and signals.

Rwl.angular-console (Nx Console) hit by network compromise

Incident
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and supply-chain poisoning risk. The malicious update executed when a workspace opened, harvested secrets, and exfiltrated data over HTTPS, the GitHub API, and DNS tunneling. Maintainers said the root cause was a developer machine compromise that leaked GitHub credentials, and they told users to update to 18.100.0 or later after reporting that a few users were compromised. Exposure was observed during the May 18, 2026 window from 2:36 p.m. to 2:47 p.m. CEST.

Related Happenings

Cursor Windows repo-root git.exe code execution security flaw

Vulnerability
H score9 First: 15.07.2026 13:55 Last: 15.07.2026 13:55 Sources 1

About this happening: Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...

GitHub fake-repository infostealer campaign

Campaign
H score41 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...

OpenMandriva Linux project hit by cyberattack

Incident
H score32 First: 10.07.2026 01:14 Last: 10.07.2026 01:14 Sources 1

About this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...

GitHub npm GAT publish-token mitigation guidance

Advisory/Mitigation
H score25 First: 09.07.2026 19:49 Last: 09.07.2026 19:49 Sources 1

About this happening: GitHub is steering npm users away from long-lived publish tokens as npm GATs that bypass 2FA lose direct publishing and sensitive-management abilities. The recomme...

GitHub Agentic Workflows indirect prompt injection security flaw

Vulnerability
H score27 First: 07.07.2026 17:04 Last: 07.07.2026 17:04 Sources 1

About this happening: GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...

Timeline

  1. 19.05.2026 10:49 2 articles · 1mo ago

    Rwl.angular-console (Nx Console) hit by network compromise

    Initial Disclosure

    The compromised rwl.angular-console 18.95.0 update entered the VS Code Marketplace and began running code as soon as a developer opened any workspace. That first-stage execution established the foothold for secret theft and later supply-chain abuse.

    Show sources