Skip to content

Nx

Disclosed Aug 26, 20251 year agoConfirmed

Official notice

s1ngularity: malicious Nx npm releases used AI CLIs to hunt and leak developer secrets

Malicious versions of the Nx build system were published to npm after attackers abused a flawed GitHub Actions workflow; the payload used installed AI command-line tools such as Claude, Gemini and Q to search for secrets and posted them to public repos in victims' GitHub accounts. Leaked tokens were then used to make over 5,500 private repositories public across more than 400 users and organizations.

What is known

People affectedNot stated in the sources we have
DisclosedAug 26, 2025
AttackSupply chain
Data exposedCredentials and tokens, API keys, Source code
SectorTech · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
ResearchtotalAug 26, 2025
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Nx

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.