logo

s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack

ID: 20a8ca17-ee7a-5f28-8e62-dc7144ecda7b

STIX ID: report--20a8ca17-ee7a-5f28-8e62-dc7144ecda7b

Feed Name: Wiz Blog

Threat Score
88/100

Date Published: 2025-09-03

Date Updated: 2026-05-01

...
...

Wiz Research details the 's1ngularity' supply-chain attack in which a compromised npm token for Nx packages was used to publish malicious package versions that exfiltrated thousands of secrets and private repositories across multiple phases; the malware harvested environment variables, GitHub and npm tokens, and leveraged locally installed AI CLIs to enumerate potentially sensitive files, resulting in widespread credential exposure and follow-on repository disclosures, with guidance on GitHub audit log investigations and observed TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.