In May 2026, a series of coordinated attacks known as the Black May attacks targeted GitHub, leveraging vulnerabilities in the Nx Console extension. These attacks were attributed to a group called TeamPCP, which exploited supply chain weaknesses to compromise developer credentials and propagate malicious code.
What Happened
The attacks began after the release of the Shai-Hulud source code by TeamPCP. They hijacked trusted release channels and harvested credentials, leading to a significant breach of GitHub's internal systems. The Nx Console version 18.95.0 was identified as a critical vector for these attacks, with evidence suggesting that it was compromised through a series of malicious actions involving the TanStack ecosystem.
The attack chain involved multiple steps, including the forking of repositories, cache poisoning, and the extraction of sensitive tokens from memory. This allowed attackers to execute unauthorized workflows and publish malicious extensions, affecting thousands of users.
On-Chain and Web Evidence
According to SlowMist's analysis, the attack exploited vulnerabilities in the GitHub Actions framework, particularly the use of the pull_request_target event, which allowed malicious code to run in a privileged context. The compromised Nx Console extension was installed over 2.2 million times, amplifying the impact of the attack.
The attackers utilized a combination of obfuscated code and malicious packages, which were difficult to detect by traditional security measures. The incident also highlighted the failure of existing security protocols, as the SLSA (Supply Chain Levels for Software Artifacts) and Sigstore mechanisms proved insufficient to guarantee the safety of the code being executed.
Why It Matters
The implications of the Black May attacks extend beyond GitHub. They underscore the vulnerabilities inherent in software supply chains and the critical need for enhanced security measures. Organizations must reassess their dependency management practices and the security of their development environments.
Immediate actions recommended include upgrading vulnerable software, conducting thorough audits of development environments, and implementing stricter controls on code execution permissions. The incident serves as a reminder that even widely trusted tools can become vectors for significant security breaches.
As the investigation continues, organizations should remain vigilant and proactive in addressing potential vulnerabilities to mitigate the risk of similar attacks in the future.
- Privileged workflow
- An automation workflow that can access protected secrets, tokens, or write permissions and therefore requires strict control over untrusted code.
Readers can separately inspect a destination with TrustSniffer’s website-risk checker; that result should be evaluated independently from the incident claims summarized here.
For broader context, the TrustSniffer Risk Index separates aggregate platform coverage from conclusions about any single domain or package.



