Attackers took over the publisher token for Nx Console, which has about 2.2 million installs. They...

Nx Console 18.95.0 fetched a 498 KB stealer via GitHub orphan commit, exposing developer secrets and forcing credential rotation.

GitHub blamed the latest in a growing list of hacks claimed by TeamPCP on a poisoned VS Code extension.