GitHub confirms 3800 internal repositories were leaked after an employee installed a poisoned Nx Console VS Code extension
Original title: GitHub Confirms 3,800 Internal Repos Exfiltrated After Employee Installed Poisoned Nx Console VS Code Extension
GitHub confirms that roughly 3800 internal repositories were leaked, including Copilot's internal code and GitHub Actions workflow source code, after an employee installed an Nx Console 18.95.0 VS Code extension poisoned by TeamPCP.
The timeline and technical chain are complete, showing how a VS Code extension supply-chain poisoning attack stole credentials and leaked internal repositories.
2026-05-22
CriticalVendor post
GitHub Confirms 3,800 Internal Repos Exfiltrated After Employee Installed Poisoned Nx Console VS Code Extension
GitHub confirmed 3,800 internal repos — including Copilot and GitHub Actions source — were exfiltrated after a TeamPCP-poisoned Nx Console VS Code extension harvested AWS, GitHub, and Claude Code API keys.
Nx Console / VS Code MarketplaceCredential exposureDeveloper credential theft / internal repository exfiltrationGitHub internal repositories / developer workstation credential stores
What happened
Poisoned VS Code extension harvested multi-platform developer credentials; stolen GitHub credentials used to exfiltrate ~3,800 internal repositories including Copilot and GitHub Actions source
Why it matters
3,800 GitHub internal repos exfiltrated including Copilot internals and GitHub Actions workflow source; AWS, GitHub, Kubernetes, GCP/Docker, and Claude Code API keys compromised; stolen data listed for $50K on dark web forums
Missing authorization check
Not applicable: no agent authorization boundary was crossed in this incident.
Would PP block it?
The compromise ran through package, credential, or vendor infrastructure rather than through an agent tool call, so there is no agent action for an authorization gate to hold.
Incident analysis
Timeline and technical read
Timeline
2026-05-19
TeamPCP poisons Nx Console 18.95.0 as part of the Mini Shai-Hulud supply chain campaign; malicious version available on VS Code Marketplace for ~18 minutes, OpenVSX for ~36 minutes
2026-05-20
GitHub employee installs poisoned Nx Console extension; payload harvests credentials for GitHub (via gh CLI), AWS, Kubernetes, GCP/Docker, and Claude Code
2026-05-20
TeamPCP uses stolen GitHub credentials to exfiltrate ~3,800 internal GitHub repositories including Copilot internals and GitHub Actions workflow source
2026-05-21
GitHub detects compromise, isolates endpoint, removes malicious extension from VS Code Marketplace, begins rotating critical secrets; TeamPCP lists stolen repos on Breached forum for $50K minimum
2026-05-22
GitHub CISO Alexis Wales publishes blog post confirming Nx Console as the attack vector; GitHub links breach to TanStack npm supply-chain attack; Nx team confirms developer was compromised via stolen gh CLI credentials
Technical breakdown
- The attack exploited the VS Code extension update pipeline: Nx Console 18.95.0 was poisoned by compromising the TanStack build infrastructure (itself breached in the broader Mini Shai-Hulud campaign), giving TeamPCP a trusted auto-update delivery channel into developer workstations.
- The malicious extension payload targeted developer credential stores broadly — npm tokens, AWS access keys, Kubernetes configs, GCP/Docker credentials, GitHub tokens via the gh CLI, and Claude Code API keys — treating the developer workstation as a credential harvesting surface.
- Stolen GitHub credentials were used to run workflows and clone repositories 'as a contributor,' bypassing GitHub's IP allowlists and authentication controls because the credentials were legitimately issued to the victim developer.
- The 18-minute marketplace availability window was sufficient for real-world compromise: low download counts (28 on VS Code Marketplace, 41 on OpenVSX) still resulted in at least one GitHub employee installation — demonstrating that supply chain attacks don't require wide distribution to cause critical impact.
- Harvested Claude Code API keys mean attackers can now impersonate developer agent sessions — submitting code changes, triggering CI/CD pipelines, or accessing codebases through the agentic surface with full credential legitimacy but without the credential owner's knowledge or intent.
Authorization boundary
Where the authorization boundary should have been
This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
- If enforced at
- Credential Gate (agent session authorization, not credential possession)
- Still needs
- VS Code extension marketplace trust; local developer credential store security; native CLI operations outside PP-instrumented agent runtimes
- Receipt required for
- Any agent action using harvested credentials — repository clones, workflow triggers, deployment operations, API calls on behalf of the credential owner
No agent took an action in this incident. Permission Protocol gates what an agent does, so it does not apply where the harm required no agent action.
Start small
Put the relevant gate at this action boundary.
This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.
Source: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com