Security1 distinct publisher3 min readPublished
CISA says a trojanized extension version, 18.95.0, reached a GitHub employee's machine without anyone installing it, and internal repositories left from there. CVE-2026-48027 is now in the KEV catalog.
The Watch · Security desk
build
56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet1 distinct publisher
security
Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build1 distinct publisher
build
Your scanner finds it in seconds; the average fix now takes 252 days1 distinct publisher
build
Amazon Q executed code from any repo you opened, and it is not the only one1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
Four systems carry the chain from Nx to GitHub, and no developer action triggers any step in it. Nx developer systems were compromised first, and CISA says that access is what produced the poisoned third-party VS Code extension [1]. The malicious build carried the version number 18.95.0 [2]. VS Code's automatic update mechanism then distributed it to machines where Nx Console was already installed, which took the operator out of the decision entirely [3]. One of those machines belonged to a GitHub employee, and internal GitHub repositories were exfiltrated from it [1].
The same alert offers package-repository hygiene: wait at least three hours before pulling a new package, pin to specific trusted versions, pull only from known sources [11]. Each of those controls sits at the moment a human or a build script decides to fetch something. An extension that updates itself has already fetched it. The guidance is sound for npm and PyPI and has nothing to grip in a marketplace auto-update path, which is why version inventory on developer endpoints, rather than pull discipline, is the control that would have caught 18.95.0 [3].
The date to work from is May 18, 2026. CISA tells defenders to revert unauthorized changes from automated accounts and singles out changes made after that date, naming patterns like build-bot, auto-ci, ci-bot and pipeline-bot [8]. The alert itself was published on May 28 [13], so the minimum audit window on an affected repository is ten days of bot-authored commits and pull requests [14][7].
CISA publishes no repository count and names no repositories [17]. It points instead to GitHub's advisory on unauthorized access to GitHub-owned repositories and to Nx's postmortem on 18.95.0 [12]. Megalodon appears in the same alert as a separate campaign, injecting malicious GitHub Action workflows into public repositories to harvest CI/CD secrets, cloud credentials and tokens [6], and CISA does not place the two behind a single actor [16]. CISA groups both campaigns under one alert, and both target the automation layer, not a code flaw [15].
CVE-2026-48027 covers one specific malicious build of Nx Console: version 18.95.0 itself is the vulnerability, not any flaw in the product's code. That entry is in the Known Exploited Vulnerabilities catalog [4]. Triage phrased as "are we running a vulnerable version" returns a useless answer here. The question is whether any extension host in the estate ever resolved 18.95.0 [2][3].
If one did, the cleanup CISA describes runs well past uninstalling an extension. The rotation list covers every credential, token and secret a pipeline can reach: API keys, AWS, GCP and Azure credentials, SSH keys, Docker, npm, PyPI, Vault, Terraform and Kubernetes tokens, and GitHub, GitLab and Bitbucket tokens [10]. Forensics covers CI/CD logs, cloud audit trails and the developer machines themselves [9]. For most affected teams, that rotation list is the bill.
Ranked by verification strength, evidence, and original report placement.
CISA says threat actors leveraged a prior compromise of Nx developer systems to compromise a GitHub employee's device through a poisoned third-party VS Code extension, resulting in unauthorized access and exfiltration of internal GitHub repositories.
The malicious Nx Console extension version was 18.95.0.
The malicious version was distributed through VS Code's automatic update mechanism, meaning systems with Nx Console previously installed may have received the malicious build without developers taking any manual installation action.
CVE-2026-48027 has been assigned to the malicious version of Nx Console and added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
GitHub released a security advisory on this activity.
In a campaign known as Megalodon, a threat actor injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials and tokens, impacting both development and deployment pipelines in public GitHub repositories.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single authoritative primary source, specific artifacts
The cluster rests on one government advisory, but that advisory is the primary authority and it is unusually specific: a named extension version (18.95.0), an assigned CVE with KEV listing, a named delivery mechanism, a dated revert cutoff, and an enumerated remediation scope. It loses points because no independent item in the cluster corroborates it and the referenced GitHub, Nx and vendor reports are cited rather than supplied, and because key facts about scope are absent.
Confirmed real-world exploitation, unquantified footprint
This is an incident story, and the observable footprint is real: exploitation is confirmed strongly enough for KEV inclusion, a GitHub employee device and internal repositories were actually affected, GitHub issued an advisory, and Megalodon is described as spreading across public GitHub repositories. What holds the score down is that CISA supplies no counts - no number of affected installs, organizations, or exfiltrated repositories - so the breadth of impact cannot be measured from the supplied material.
Slightly understated relative to severity
The advisory's register is procedural rather than promotional: it states the intrusion chain and remediation steps without severity adjectives, and it explicitly declines to link the two campaigns or name an actor. Given that the outcome includes exfiltration of a major code host's internal repositories, distribution via silent auto-update, and a ten-day lag behind the stated revert cutoff, the framing sits slightly below what the underlying facts would support, so the gap is mildly negative rather than positive.
Low: government advisory with explicit non-endorsement
The sole publisher is the issuing government agency, whose interest is remediation uptake rather than commercial gain, and the alert carries an explicit disclaimer that CISA does not endorse any commercial entity, product, or service. Some residual incentive pressure exists because the alert amplifies vendor research from Ox Security, StepSecurity and SafeDep alongside first-party writeups from GitHub and Nx, parties with reputational and commercial stakes in the narrative.
High on facts asserted, low on scope
Confidence is high that the asserted facts are accurate: they come directly from the responsible federal agency, are internally consistent, and are anchored by a CVE, a KEV listing and a named version. Confidence is lower on interpretation and consequence, because the cluster has a single publisher, the scope of exfiltration is undisclosed, attribution is absent, and the referenced corroborating reports are not part of the supplied material.