logo

s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know

ID: 046f319d-407e-5ee9-a735-5b884e1cc032

STIX ID: report--046f319d-407e-5ee9-a735-5b884e1cc032

Feed Name: Wiz Blog

Threat Score
88/100

Date Published: 2025-08-27

Date Updated: 2026-05-01

...
...

On 26 August 2025 malicious versions of the Nx npm packages contained a post‑install telemetry.js that ran on Linux/macOS, harvested developer secrets (wallets, gh/npm tokens, SSH keys, .env, etc.), and uploaded base64‑encoded data to attacker GitHub repositories; stolen GitHub tokens were later abused to publish thousands of private repositories publicly, impacting hundreds of users/organizations. Immediate remediation recommended includes removing the malicious package versions, cleaning affected shells and temp files, rotating all exposed credentials and keys, and auditing GitHub logs and CI/dev endpoints for indicators listed in the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.