ClosedMedium impactAI Generated

CISA Advisory: Nx Console & GitHub Supply Chain Compromises

Occurred 18 May 2026Β·Detected 28 May 2026Β·
πŸ‡ΊπŸ‡Έ Global software supply chain incident; primary known victim (GitHub) headquartered in San Francisco, CA, USA; broad global enterprise exposure1 reportEnded 29 May 2026
CyberCyberCasualty & Liability

CISA has issued an advisory on two active software supply chain intrusion campaigns: a compromise of GitHub via a malicious Nx Console VS Code extension (CVE-2026-48027), and the 'Megalodon' campaign injecting malicious GitHub Action workflows to harvest CI/CD secrets and cloud credentials. The incidents affect enterprise, cloud, and DevOps environments globally, with potential for broad credential theft across AWS, GCP, Azure, and other platforms. While technically significant, no named insured entities, quantified losses, or confirmed claims have been identified, limiting immediate London Market materiality.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. Loss pathway: Widespread credential harvesting across enterprise CI/CD pipelines creates plausible downstream cyber insurance loss pathway via ransomware deployment, data exfiltration, or business interruption using harvested cloud credentials. Evidence: CISA KEV listing, confirmed exfiltration of GitHub internal repositories, and broad scope of affected credential types (AWS, GCP, Azure, SSH, Docker tokens) indicate material exposure across cyber insurance books. Limit: No named insured commercial entities confirmed as victims, no quantified loss estimates, and no confirmed downstream attacks reported β€” impact remains potential rather than realized, warranting monitoring rather than immediate claims action.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

πŸ‡¬πŸ‡§ United KingdomπŸ‡ΊπŸ‡Έ United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts