Rwl.angular-console (Nx Console) hit by network compromise
Incident
Summary
Hide ▲
Show ▼
The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and supply-chain poisoning risk. The malicious update executed when a workspace opened, harvested secrets, and exfiltrated data over HTTPS, the GitHub API, and DNS tunneling. Maintainers said the root cause was a developer machine compromise that leaked GitHub credentials, and they told users to update to 18.100.0 or later after reporting that a few users were compromised. Exposure was observed during the May 18, 2026 window from 2:36 p.m. to 2:47 p.m. CEST.
Related Happenings
Cursor Windows repo-root git.exe code execution security flaw
Vulnerability
H score9
First: 15.07.2026 13:55
Last: 15.07.2026 13:55
Sources 1
About this happening:
Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...
Cursor Windows repo-root git.exe code execution security flaw
VulnerabilityAbout this happening: Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...
GitHub fake-repository infostealer campaign
Campaign
H score41
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
GitHub fake-repository infostealer campaign
CampaignAbout this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
OpenMandriva Linux project hit by cyberattack
Incident
H score32
First: 10.07.2026 01:14
Last: 10.07.2026 01:14
Sources 1
About this happening:
The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
OpenMandriva Linux project hit by cyberattack
IncidentAbout this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
GitHub npm GAT publish-token mitigation guidance
Advisory/Mitigation
H score25
First: 09.07.2026 19:49
Last: 09.07.2026 19:49
Sources 1
About this happening:
GitHub is steering npm users away from long-lived publish tokens as npm GATs that bypass 2FA lose direct publishing and sensitive-management abilities. The recomme...
GitHub npm GAT publish-token mitigation guidance
Advisory/MitigationAbout this happening: GitHub is steering npm users away from long-lived publish tokens as npm GATs that bypass 2FA lose direct publishing and sensitive-management abilities. The recomme...
GitHub Agentic Workflows indirect prompt injection security flaw
Vulnerability
H score27
First: 07.07.2026 17:04
Last: 07.07.2026 17:04
Sources 1
About this happening:
GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...
GitHub Agentic Workflows indirect prompt injection security flaw
VulnerabilityAbout this happening: GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...
Timeline
-
19.05.2026 10:49 2 articles · 1mo ago
Rwl.angular-console (Nx Console) hit by network compromise
Initial DisclosureThe compromised rwl.angular-console 18.95.0 update entered the VS Code Marketplace and began running code as soon as a developer opened any workspace. That first-stage execution established the foothold for secret theft and later supply-chain abuse.
Show sources
- Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer — thehackernews.com — 19.05.2026 10:49
- Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer — thehackernews.com — 19.05.2026 10:49