In May 2026, a series of coordinated attacks known as the Black May attacks targeted GitHub, leveraging vulnerabilities in the Nx Console extension. These attacks were attributed to a group called TeamPCP, which exploited supply chain weaknesses to compromise developer credentials and propagate malicious code.

What Happened

The attacks began after the release of the Shai-Hulud source code by TeamPCP. They hijacked trusted release channels and harvested credentials, leading to a significant breach of GitHub's internal systems. The Nx Console version 18.95.0 was identified as a critical vector for these attacks, with evidence suggesting that it was compromised through a series of malicious actions involving the TanStack ecosystem.

The attack chain involved multiple steps, including the forking of repositories, cache poisoning, and the extraction of sensitive tokens from memory. This allowed attackers to execute unauthorized workflows and publish malicious extensions, affecting thousands of users.

Read as a sequence, the chain matters more than any single step in it. A trusted release channel was hijacked, credentials were harvested, and those credentials were then used to run workflows and publish an extension that developers had no reason to distrust. At no point did the reported activity require the developer to do anything unusual: installing or updating Nx Console through the normal channel was enough to be exposed. That is why the reported install count describes the scale of the exposure rather than the number of people who were deliberately targeted.

On-Chain and Web Evidence

According to SlowMist's analysis, the attack exploited vulnerabilities in the GitHub Actions framework, particularly the use of the pull_request_target event, which allowed malicious code to run in a privileged context. The compromised Nx Console extension was installed over 2.2 million times, amplifying the impact of the attack.

The attackers utilized a combination of obfuscated code and malicious packages, which were difficult to detect by traditional security measures. The incident also highlighted the failure of existing security protocols, as the SLSA (Supply Chain Levels for Software Artifacts) and Sigstore mechanisms proved insufficient to guarantee the safety of the code being executed.

At assessment time the evidence points at one pivot rather than at a long list of separate bugs. An automation job that could reach protected secrets and write permissions was allowed to run code from an untrusted source, and the pull_request_target event supplied that privileged context. The rest of the reported steps follow from it: forking repositories, poisoning caches, pulling tokens out of memory, and then publishing packages under a name that already carried trust. It also explains why signing and provenance checks did not stop the activity, since the cited material indicates that SLSA and Sigstore did not guarantee the safety of the code actually being executed.

Why It Matters

The implications of the Black May attacks extend beyond GitHub. They underscore the vulnerabilities inherent in software supply chains and the critical need for enhanced security measures. Organizations must reassess their dependency management practices and the security of their development environments.

Immediate actions recommended include upgrading vulnerable software, conducting thorough audits of development environments, and implementing stricter controls on code execution permissions. The incident serves as a reminder that even widely trusted tools can become vectors for significant security breaches.

As the investigation continues, organizations should remain vigilant and proactive in addressing potential vulnerabilities to mitigate the risk of similar attacks in the future.

For readers who are not running a security team, the practical takeaway is narrower than the headline. What is described here is limited to the reported incident and to the software and workflows named in it, so any other domain, extension, or repository needs its own separate assessment before you treat it as clean or compromised. If a link or destination is involved, you can look at it on its own with the website-risk checker, and if an address or wallet comes into the picture, the wallet checker answers that as a distinct question rather than an extension of this incident.


Privileged workflow
An automation workflow that can access protected secrets, tokens, or write permissions and therefore requires strict control over untrusted code.

Readers can separately inspect a destination with TrustSniffer’s website-risk checker; that result should be evaluated independently from the incident claims summarized here.

For broader context, the TrustSniffer Risk Index separates aggregate platform coverage from conclusions about any single domain or package.

Sources

Frequently asked questions

What does this analysis of Analysis of the GitHub Breach Linked to Black May Attacks establish?

In May 2026, a series of coordinated attacks known as the Black May attacks targeted GitHub, leveraging vulnerabilities in the Nx Console extension.

What evidence should readers verify?

Check the dated technical or official sources listed below, then compare their statements with the specific claims and limitations in this article.

Does this article prove that every related system or address is unsafe?

No. The analysis is limited to the reported incident and cited evidence. Related names, software, domains, or addresses require separate assessment.

What is the practical next step?

Verify the exact identifier or version involved, preserve relevant records, and use the appropriate security or compliance review before taking consequential action.