TeamTCP Nx Console Extension Supply Chain Attack | MSSP Advisory
HighCredible Report
DateMay 21, 2026
📋Executive Summary
GitHub and Grafana Labs suffered breaches after the TeamTCP threat group compromised the Nx Console VS Code extension, a developer tool with 2.2 million installs. The malicious extension version harvested developer credentials and secrets, enabling attackers to traverse CI/CD pipelines and exfiltrate 3,800 private GitHub repositories through what appears to be a broader TanStack supply chain attack.
⚠️Why It Matters for MSSPs
Your RMM and PSA environments likely run VS Code instances for custom scripting and integration work, making your credential stores and client access tokens direct targets if this extension was installed. Every client running development operations with VS Code faces potential credential theft and repository compromise, which means you need to audit their development environments immediately or risk missing a major breach in progress.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Supply Chain
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.