SecurityHorrors

Stories you never want to feel on your own skin

20 May 2026

GitHub: The Extension That Opened the Vault

TLDR and impact summary for the GitHub internal repository breach caused by a malicious VS Code extension installed by a GitHub developer.

19 May 2026

Nx Console: One Stolen Token, One Poisoned Marketplace

TLDR and affected version summary for the Nx Console VS Code extension compromise via a contributor's leaked GitHub PAT.