logo

Popular nx packages compromised on npm

ID: fc591b10-4936-5fa7-9d0e-b3e56b1ecb52

STIX ID: report--fc591b10-4936-5fa7-9d0e-b3e56b1ecb52

Feed Name: Aikido Security's Blog

Threat Score
85/100

Date Published: 2025-08-27

Date Updated: 2026-07-24

...
...

A malicious postinstall payload was injected into several @nx npm packages (multiple specified versions) that collected local secrets (wallets, SSH keys, .env, .npmrc), harvested GitHub and npm credentials, appended a shutdown command to shell profiles, and exfiltrated the data by creating public GitHub repositories (s1ngularity-repository[-X]) containing double-base64-encoded results; affected users should check for created repos, rotate all secrets, and remove the shutdown entry from shell profiles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.