logo

Nx NPM packages poisoned in AI-assisted supply chain attack

ID: 6b6d4756-c5ec-50b8-b3cd-4d412dafc857

STIX ID: report--6b6d4756-c5ec-50b8-b3cd-4d412dafc857

Feed Name: The Register (Security)

Threat Score
87/100

Date Published: 2025-08-27

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Nx, a widely used NPM project, was targeted in a supply‑chain attack where malicious package versions published to the NPM registry stole developer secrets (GitHub and NPM tokens, SSH keys, cloud credentials, and crypto wallet details) and the attacker publicly posted stolen data to GitHub; researchers report roughly 1,000 valid GitHub tokens and ~20,000 files exposed. The malware coerced locally installed generative AI CLIs to scan file systems for sensitive paths and also inserted a shutdown command into startup files; NPM removed the affected versions within an hour of being alerted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.