1,000+ Devs Lose Their Secrets to an AI-Powered Stealer
ID: d1958065-e4fc-5c4f-a2be-2643bca2e4aa
STIX ID: report--d1958065-e4fc-5c4f-a2be-2643bca2e4aa
Feed Name: Dark Reading
A rapid supply-chain compromise of the Nx npm ecosystem delivered a malicious telemetry.js script that harvested GitHub/npm tokens, SSH keys, application secrets, and wallet files from developers. The malware augmented file discovery using AI CLI tools, exfiltrated sensitive data by creating public "singularity-repository-*" GitHub repos containing base64-encoded results, and modified shell startup files to disrupt recovery. Npm and GitHub removed the malicious uploads and repositories, but vendors observed over 1,000 affected accounts and roughly 20,000 leaked files, with many tokens still active.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
