In May 2026, attackers stole about 3,800 of GitHub's internal code repositories. The route ran through a chain of stolen developer credentials. The TeamPCP group's "Mini Shai-Hulud" worm compromised TanStack npm packages, which leaked an Nx developer's GitHub CLI token. The attacker used that token to run Nx's publishing workflow and pushed a malicious version of the Nx Console VS Code extension, which has 2.2 million installs. It was live for about 18 minutes. A GitHub employee's machine picked it up, and the extension's payload harvested credentials including Vault tokens, AWS and Kubernetes credentials, npm tokens, GitHub tokens and 1Password vault contents. The stolen credentials were used to exfiltrate GitHub's internal repositories. Grafana Labs was hit through the same TanStack compromise because of one missed workflow token. Every link in the chain was a developer or pipeline credential.
Key takeaways
- GitHub confirmed on 19 and 20 May 2026 that attackers exfiltrated internal repositories after an employee installed a poisoned VS Code extension. It said the attacker's claim of about 3,800 repositories was "directionally consistent" with its investigation.
- Nx says an Nx developer was compromised through the TanStack npm attack, "which leaked their GitHub credentials through the GitHub CLI (gh)", letting the attacker run workflows on Nx's repository as a contributor.
- Nx Console 18.95.0 was published on 18 May "without manual approval" from other Nx administrators, and was live for about 18 minutes on the Visual Studio Marketplace and 36 minutes on Open VSX.
- The payload harvested Vault tokens, AWS credentials from metadata services, Secrets Manager and SSM, npm tokens, GitHub tokens and Actions secrets, 1Password CLI vault contents, private keys and GCP and Docker credentials.
- Grafana Labs was breached through the same TanStack campaign. It rotated many GitHub workflow tokens, "but a missed token led to the attackers gaining access to our GitHub repositories."
At a glance
| Organisations | GitHub (internal repositories); Nx (Nx Console extension); TanStack (npm packages); Grafana Labs; users of Nx Console 18.95.0 |
|---|---|
| When | TanStack compromise around 11 May 2026; malicious Nx Console published 18 May 2026; GitHub disclosure 19 to 20 May 2026 |
| Attacker | TeamPCP (also tracked as UNC6780), a cybercrime group behind the Mini Shai-Hulud worm, which claimed the GitHub breach and offered the code for sale |
| Entry point | A malicious Nx Console VS Code extension installed on a GitHub employee's device, itself published with a GitHub CLI token stolen in the TanStack compromise |
| Identities abused | An Nx developer's GitHub CLI token; the employee's developer credentials, including Vault, AWS, Kubernetes, npm, GitHub and 1Password secrets; GitHub workflow tokens at Grafana Labs |
| Impact | About 3,800 GitHub internal repositories exfiltrated; Grafana Labs codebase stolen; thousands of Nx Console users potentially exposed |
| Category | NHI. Incident class: confirmed NHI breach (developer and CI tokens stolen and used to reach GitHub's internal code) |
What happened
The chain started with TanStack, a popular set of open-source web development libraries. TeamPCP's self-replicating Mini Shai-Hulud worm compromised 42 TanStack npm packages, according to Help Net Security, and spread to projects including Mistral AI, UiPath, Guardrails AI and OpenSearch using stolen CI/CD credentials. One victim was an Nx developer. Nx explained: "One of our developers was compromised by a recent supply-chain compromise on TanStack, which leaked their GitHub credentials through the GitHub CLI (gh). This allowed the attacker to run workflows on our GitHub repository as a contributor."
On 18 May, a malicious Nx Console version 18.95.0 was uploaded to the Visual Studio Marketplace and Open VSX at 12:30 UTC by someone posing as a legitimate Nx maintainer. Nx CEO Jeff Cross said the upload happened "without manual approval" from other Nx administrators. It was pulled within minutes, and Microsoft completed the takedown at 12:48 UTC. Marketplace counts showed 28 and 41 downloads, but Nx's analytics recorded about 6,000 extension activations in two days, because auto-update installs quickly. The issue was assigned CVE-2026-48027.
The extension fetched an obfuscated payload that harvested credentials from disk and memory. According to Infosecurity Magazine's summary of Nx's report, it took Vault tokens, Kubernetes and AWS IAM authentication, npm tokens and OIDC token exchange, AWS metadata, Secrets Manager, SSM and web identity tokens, GitHub tokens, Actions secrets and process memory, 1Password CLI vault contents, private keys, connection strings and GCP and Docker credentials. Nx says data was exfiltrated over HTTPS, the GitHub API and DNS.
A GitHub employee's device was one of those affected. GitHub said on 19 May it had "removed the malicious extension version, isolated the endpoint, and began incident response immediately". It added: "Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker's current claims of ~3,800 repositories are directionally consistent with our investigation so far." GitHub CISO Alexis Wales named Nx Console on 20 May and said: "We rotated critical secrets Monday and into Tuesday with the highest-impact credentials prioritized first." TeamPCP claimed the breach on a criminal forum and asked for at least $50,000 for the code. Grafana Labs separately traced its own code theft to the TanStack attack. Its CISO, Joe McManus, said it "quickly rotated a significant number of GitHub workflow tokens, but a missed token led to the attackers gaining access to our GitHub repositories."
Timeline
| Date | Event |
|---|---|
| 11 May 2026 | Grafana Labs detects malicious activity linked to the TanStack npm compromise. |
| 18 May 2026 | Malicious Nx Console 18.95.0 published at 12:30 UTC using access from a stolen GitHub CLI token; removed from the Visual Studio Marketplace by 12:48 UTC. |
| 19 May 2026 | GitHub reports unauthorised access to internal repositories via a poisoned VS Code extension on an employee device. |
| 20 May 2026 | GitHub confirms exfiltration of internal repositories and names Nx Console as the extension. |
| 21 May 2026 | BleepingComputer and Help Net Security report the link to the TanStack attack. |
How it happened: the identity attack path
- A worm that feeds on CI credentials. Mini Shai-Hulud stole CI/CD and publishing credentials to push infected versions of TanStack and other packages.
- A developer's CLI token leaked. The TanStack compromise exposed an Nx developer's GitHub CLI credentials.
- Workflows run as a contributor. With that token, the attacker ran Nx's GitHub workflows and published a malicious extension without a second approval.
- An extension with full access to a developer machine. VS Code extensions run with the developer's permissions, so the payload could read every credential on disk and in memory.
- Secrets harvested at scale. Vault tokens, cloud credentials, registry tokens, GitHub tokens and password manager contents were collected from each infected machine.
- Stolen credentials used for exfiltration. At GitHub, the harvested credentials gave access to internal repositories. At Grafana Labs, a single unrotated workflow token did the same.
Impact
- GitHub: about 3,800 internal repositories exfiltrated; no evidence so far of customer data outside those repositories being affected, according to GitHub.
- Grafana Labs: codebase stolen; the company refused the attackers' payment demand.
- Nx Console users: thousands of potentially affected developers, advised to rotate every credential reachable from their machines.
- Ecosystem: one of a series of TeamPCP compromises that has also hit Trivy, KICS and LiteLLM.
What this means for NHI and AI agent security
This breach is a relay race of non-human identities. A worm stole CI credentials, which exposed a developer's CLI token. That token published a poisoned extension, which stole hundreds of secrets from a developer machine, and those secrets opened one of the world's most important code platforms. At no point did the attacker need to break a strong authentication control. Each step used a credential that was valid, long-lived and broader than the moment required.
Two details stand out for identity teams. First, publishing rights were effectively held by a single token, with no second approval, so one leaked credential could ship code to millions of installs. Second, Grafana Labs' "missed token" shows why rotation after exposure must be complete and verified. Rotating most workflow tokens is not the same as rotating all of them. Our CI/CD Pipeline Identity Security Guide and Guide to NHI Rotation Challenges cover both.
Recommendations
- Require multi-party approval to publish. No single token or maintainer should be able to release an extension or package. Nx now requires two admins to approve releases.
- Replace long-lived CLI and publishing tokens. Use short-lived, scoped tokens and OIDC-based trusted publishing, and bind CLI sessions to devices. See our Token and Session Security Guide.
- Treat developer machines as credential stores. Keep production and admin credentials off laptops, limit what Vault and cloud sessions on a developer device can reach, and expire them quickly. See our AI Coding Agents Security Guide.
- Control IDE extensions. Allow-list approved extensions, delay auto-updates for new versions, and monitor extension changes on managed devices.
- Rotate completely and verify. After exposure, rotate every credential reachable from affected machines and pipelines, then confirm nothing was missed. Use our Leaked Credential Response Playbook.
Frequently asked questions
How was GitHub breached in May 2026?
A GitHub employee's device installed a malicious version of the Nx Console VS Code extension. Its payload stole developer credentials, which were used to exfiltrate about 3,800 of GitHub's internal repositories. The malicious extension had been published using a GitHub CLI token stolen from an Nx developer in the TanStack npm supply chain attack.
Was GitHub customer data affected?
GitHub said its assessment was that the activity involved exfiltration of GitHub-internal repositories only, and that it had no evidence that customer information stored outside those repositories was affected.
What should Nx Console users do?
Anyone who ran Nx Console 18.95.0 should assume compromise and rotate every credential reachable from the machine, including tokens, SSH keys, cloud credentials, Vault tokens and password manager secrets.
Related NHI Mgmt Group resources
LiteLLM PyPI package breach · Shai-Hulud npm campaign · Megalodon GitHub Actions attack 2026 · GlassWorm VS Code extension worm · CI/CD Pipeline Identity Security Guide
How NHI Mgmt Group can help
Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as attackers chain developer, CLI and pipeline tokens from one project to the next. Our NHI Foundation Level Training Course gives teams the practical grounding to break those chains.
References
- Help Net Security: TeamPCP breached GitHub's internal codebase via poisoned VS Code extension (20 May 2026)
- BleepingComputer: GitHub links repo breach to TanStack npm supply-chain attack (21 May 2026)
- Help Net Security: GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise (21 May 2026)
- Infosecurity Magazine: GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension (21 May 2026)