←── back to feed
/topics/github-unauthorized-access-investigation

GitHub unauthorized access investigation

4 items1 sourcesupdated 27d agotrend 0

GitHub is investigating unauthorized access to internal repositories, with the Nx Console VS Code extension identified as the initial attack vector. The breach exposed sensitive credentials, including CISA secrets found in public repositories.

  • Nx Console VS Code extension served as entry point for unauthorized access
  • GitHub internal repositories were compromised during the incident
  • CISA credentials were exposed and discovered in public GitHub repositories
  • Investigation began around May 19-20, 2026