Alert - AL26-013 Security incident impacting GitHub internal repositories

Number: AL26-013
Date: May 29, 2026

Audience

This Alert is intended for IT professionals and managers.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Details

On May 18, 2026, GitHub detected unauthorized access to its internal systems originating from a compromised employee deviceFootnote 1. The intrusion was facilitated by a maliciously modified version of the Nx Console Visual Studio Code extension (version 18.95.0)Footnote 2. The attacker successfully exfiltrated approximately 3,800 internal GitHub repositories, containing proprietary source code and internal configuration data. GitHub Enterprise Server customers are advised to follow vendors recommendations. No action is required for GitHub Enterprise Cloud clients.

In response to this security incident, and the release of the GitHub Security Notification, the Cyber Centre released AV26-512 on May 27, 2026Footnote 3.

The purpose of this alert is to increase awareness of the reported incident and to take necessary measures.

Suggested actions

The Cyber Centre suggests the following actions:

  • Monitor for compromise by reviewing CI/CD (Continuous Integration/Continuous Deployment) logs for unexpected repository access/cloning, unauthorized admin actions, authentication/access control changes, unauthorized pushes or orphan commits, and suspicious commits after May 18, 2026 — especially from bot/service accounts (e.g., ci-bot, build-bot).
  • Remove Nx Console v18.95.0 from all environments and downgrade/upgrade to a known good version (18.94.0 or 18.96.0+).
  • If the malicious version of Nx Console is present:
    • Check macOS systems for ~/.local/share/kitty/cat.py and related persistence (launch agents)
    • Immediately rotate all credentials (AWS, GCP, Azure, GitHub, npm) exposed on developer machines between May 11–20, 2026.
  • Strengthen controls by disabling IDE extension auto-updates in high-security environments and enforcing an approved allowlist of developer tools.
  • Rotate GitHub Enterprise Server GPG (GNU Privacy Guard) public keys per vendor guidance, as future patches/releases require the new key before installation.

In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions with an emphasis on the following topicsFootnote 4.

  • Patch operating systems and applications
  • Harden operating systems and applications
  • Isolate web-facing applications

Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal, or email contact@cyber.gc.ca.

Date modified: