logo

Nx Package Supply Chain Compromise Delivers Data-Stealing Malware (Campaign)

ID: ff3fecbe-9360-5bec-9248-b8682d287d26

STIX ID: report--ff3fecbe-9360-5bec-9248-b8682d287d26

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2025-08-27

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

A compromised npm package (malicious telemetry.js) delivered data-stealing malware that targeted Linux and macOS systems to collect sensitive files and credentials, weaponized AI CLI tools to access filesystem contents, appended shutdown commands to shell startup files, and exfiltrated base64-encoded data to thousands of attacker GitHub repositories (e.g., s1ngularity-repository*); GitHub disabled the repositories after an ~8-hour exposure window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.