s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know
ID: 046f319d-407e-5ee9-a735-5b884e1cc032
STIX ID: report--046f319d-407e-5ee9-a735-5b884e1cc032
Feed Name: Wiz Blog
On 26 August 2025 malicious versions of the Nx npm packages contained a post‑install telemetry.js that ran on Linux/macOS, harvested developer secrets (wallets, gh/npm tokens, SSH keys, .env, etc.), and uploaded base64‑encoded data to attacker GitHub repositories; stolen GitHub tokens were later abused to publish thousands of private repositories publicly, impacting hundreds of users/organizations. Immediate remediation recommended includes removing the malicious package versions, cleaning affected shells and temp files, rotating all exposed credentials and keys, and auditing GitHub logs and CI/dev endpoints for indicators listed in the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
