ctipilot.ch

Nx Console v18.95.0 VS Code extension supply-chain compromise — credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub PAT, AWS creds; published via stolen TanStack-leaked GitHub CLI OAuth token

cve · CVE-2026-48027

Coverage timeline
1
first 2026-05-28 → last 2026-05-28
Briefs
1
1 distinct
Sources cited
31
19 hosts
Sections touched
1
deep_dive
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-28CTI Daily Brief — 2026-05-28
    deep_diveFirst coverage. CISA KEV add 2026-05-27. Live on VS Marketplace 12:30-12:48 UTC + Open VSX 12:33-13:09 UTC on 2026-05-18. ~2.2M installs reach. GitHub CISO confirmed ~3,800 internal repos exfiltrated via this vector; Grafana Labs also breached. Safe: ≥18.100.0. Deep dive 2026-05-28.

Where this entity is cited

  • deep_dive1

Source distribution

  • attack.mitre.org9 (29%)
  • cert.ssi.gouv.fr2 (6%)
  • cisa.gov2 (6%)
  • github.com2 (6%)
  • socket.dev2 (6%)
  • blog.daemon-tools.cc1 (3%)
  • cybersecuritynews.com1 (3%)
  • helpnetsecurity.com1 (3%)
  • other11 (35%)

External references

NVD · cve.org · CISA KEV

All cited sources (31)

Items in briefs about Nx Console v18.95.0 VS Code extension supply-chain compromise — credential-stealing payload harvested 1Password, Claude Code config, npm, GitHub PAT, AWS creds; published via stolen TanStack-leaked GitHub CLI OAuth token

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.