Nx
Disclosed Aug 26, 20251 year agoConfirmed
s1ngularity: malicious Nx npm releases used AI CLIs to hunt and leak developer secrets
Malicious versions of the Nx build system were published to npm after attackers abused a flawed GitHub Actions workflow; the payload used installed AI command-line tools such as Claude, Gemini and Q to search for secrets and posted them to public repos in victims' GitHub accounts. Leaked tokens were then used to make over 5,500 private repositories public across more than 400 users and organizations.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Aug 26, 2025 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens, API keys, Source code |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Malicious versions of Nx and some supporting plugins were publishedgithub.com · Official notice | Official notice |
| s1ngularity: supply chain attack leaks secrets on GitHubwiz.io · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Aug 26, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.