CISA added three actively exploited software supply-chain vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-48027 in Nx Console, CVE-2026-45321 in TanStack npm packages, and CVE-2026-8398 in DAEMON Tools Lite. The Nx Console incident involved a malicious 18.95.0 extension published to Visual Studio Marketplace and OpenVSX after a prior compromise of Nx developer systems; CISA said the poisoned extension was automatically distributed and was used to compromise a GitHub employee device, leading to unauthorized access to and exfiltration of internal GitHub repositories. CISA identified Nx Console 18.100.0 as clean and said federal agencies must remediate the listed flaws under BOD 22-01 or discontinue use if mitigations are unavailable.
CISA also warned that the TanStack intrusion abused GitHub Actions through a pull_request_target misconfiguration, cache poisoning, and OIDC token theft to publish malicious packages, with reporting indicating 84 malicious versions across 42 packages carried valid Sigstore/SLSA provenance. In parallel, the agency highlighted the Megalodon campaign, in which attackers inserted malicious GitHub Actions workflows into public repositories to steal CI/CD secrets, cloud credentials, and tokens, and said organizations should audit workflow files and contributor activity, revert unauthorized automated-account changes, conduct forensic reviews, rotate potentially exposed secrets, delay package pulls, pin trusted versions, and use only trusted package sources. The DAEMON Tools Lite case involved trojanized signed installers reportedly distributed from the vendor’s website after a suspected compromise of build or distribution systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Reporting on the KEV additions states that Federal Civilian Executive Branch agencies were required under BOD 22-01 to remediate the newly listed vulnerabilities by a set deadline. One source gives the deadline as June 10, 2026, while another reports June 17, 2026.
CISA published an alert warning about emerging software supply-chain intrusion campaigns affecting developer ecosystems, including the Nx Console compromise and the Megalodon GitHub workflow campaign. The agency urged organizations to audit workflows and contributor activity, conduct forensic reviews, rotate exposed secrets, and use trusted package sources.
Following a prior compromise of Nx developer systems, the malicious Nx Console extension was automatically distributed and used to compromise a GitHub employee device. Attackers then gained unauthorized access to and exfiltrated internal GitHub repositories.
CISA updated its Known Exploited Vulnerabilities Catalog to add CVE-2026-48027, CVE-2026-45321, and CVE-2026-8398, covering the Nx Console, TanStack, and DAEMON Tools Lite supply-chain incidents. The update raised the catalog total from 1,603 to 1,606 vulnerabilities.
A poisoned Nx Console Visual Studio Code extension, version 18.95.0, was briefly published to the Visual Studio Marketplace and OpenVSX. The malicious release was later assigned CVE-2026-48027.
CISA warned organizations to review and revert unauthorized automated-account changes made especially after May 18, 2026, in connection with the Megalodon campaign. The campaign involved malicious GitHub Action workflows injected into public repositories to steal CI/CD secrets, cloud credentials, and tokens.
Praetorian published research describing GitHub Actions exploitation techniques involving pull_request_target and related workflow abuse. Later reporting on the TanStack compromise references these methods as part of the attack chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcethecyberthrone.in
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcegithub.com
Open sourcepraetorian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.