Rogue Agent Watch › Records › nx-s1ngularity-supply-chain
Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.
Summary
On 2025-08-26 attackers exploited a flawed GitHub Actions workflow in the Nx build tool to publish malicious versions of nx and related npm packages. A postinstall script scanned victim machines for secrets and, notably, weaponised locally installed AI CLI tools (Claude, Gemini, Amazon Q) as file-search agents to locate sensitive files, then exfiltrated stolen data to attacker-created public GitHub repositories and appended a shutdown command to shell configuration files. Disclosed via Nx's GitHub security advisory and postmortem and analysed by Wiz Research.
Impact as stated
Per Wiz: over a thousand valid GitHub tokens, dozens of valid cloud credentials and NPM tokens, and roughly twenty thousand additional files leaked; a subsequent wave made over 5,500 private repositories public across 400+ users and organisations. Malware also attempted host lockout via a shutdown command appended to shell startup files.
Facts as stated by sources
- Actor
- Unknown (Unknown)
- Category
- Infrastructure abuse / supply chain
- Models named
- Claude, Gemini, Amazon Q
- Model families
- Claude (Anthropic), Gemini (Google), Other / unspecified
- Agentic autonomy level
- Tool-assisted
- Guardrail bypass
- Legitimate tool abuse
- Attack lifecycle phases
- Resource development, Initial access, Execution, Credential access, Exfiltration, Impact
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- 400
- Records exfiltrated
- not stated
Framework mappings
Mitigations as stated
- Rotate exposed credentials and tokens; remove the malicious package versions.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Sources (3)
- S1ngularity - What Happened, How We Responded, What We Learned
Nx · First-party disclosure · · archived copy - Nx security advisory (GHSA-cxm3-wv7p-598c)
Nx / GitHub · First-party disclosure · · archived copy - s1ngularity: supply chain attack leaks secrets on GitHub
Wiz · Vendor report · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "nx-s1ngularity-supply-chain". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/nx-s1ngularity-supply-chain.json — CC BY-SA 4.0.