logo

1,000+ Devs Lose Their Secrets to an AI-Powered Stealer

ID: d1958065-e4fc-5c4f-a2be-2643bca2e4aa

STIX ID: report--d1958065-e4fc-5c4f-a2be-2643bca2e4aa

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-08-28

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

A rapid supply-chain compromise of the Nx npm ecosystem delivered a malicious telemetry.js script that harvested GitHub/npm tokens, SSH keys, application secrets, and wallet files from developers. The malware augmented file discovery using AI CLI tools, exfiltrated sensitive data by creating public "singularity-repository-*" GitHub repos containing base64-encoded results, and modified shell startup files to disrupt recovery. Npm and GitHub removed the malicious uploads and repositories, but vendors observed over 1,000 affected accounts and roughly 20,000 leaked files, with many tokens still active.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.