GitHub lost 3,800 internal repos after poisoned Nx Console update exposed developer credentials and supply-chain risk.

Nx Console 18.95.0 fetched a 498 KB stealer via GitHub orphan commit, exposing developer secrets and forcing credential rotation.

GitHub blamed the latest in a growing list of hacks claimed by TeamPCP on a poisoned VS Code extension.