Popular nx packages compromised on npm
ID: fc591b10-4936-5fa7-9d0e-b3e56b1ecb52
STIX ID: report--fc591b10-4936-5fa7-9d0e-b3e56b1ecb52
Feed Name: Aikido Security's Blog
A malicious postinstall payload was injected into several @nx npm packages (multiple specified versions) that collected local secrets (wallets, SSH keys, .env, .npmrc), harvested GitHub and npm credentials, appended a shutdown command to shell profiles, and exfiltrated the data by creating public GitHub repositories (s1ngularity-repository[-X]) containing double-base64-encoded results; affected users should check for created repos, rotate all secrets, and remove the shutdown entry from shell profiles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
