Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

On May 18, 2026, attackers compromised a developer’s machine at Nrwl and pushed a malicious update to the Nx Console VS Code extension, exposing a large population of developers for approximately 11 minutes. The payload stole developer credentials across AWS, GitHub, npm, 1Password, and Anthropic Claude Code. The most serious business risk is downstream: stolen npm OIDC tokens were used to publish poisoned packages carrying valid cryptographic provenance signatures, meaning malicious code can enter your software supply chain appearing fully trusted and verified.

Author

Tech Jacks Solutions