Rogue Agent Watch › Records › nx-s1ngularity-supply-chain

Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.

Summary

On 2025-08-26 attackers exploited a flawed GitHub Actions workflow in the Nx build tool to publish malicious versions of nx and related npm packages. A postinstall script scanned victim machines for secrets and, notably, weaponised locally installed AI CLI tools (Claude, Gemini, Amazon Q) as file-search agents to locate sensitive files, then exfiltrated stolen data to attacker-created public GitHub repositories and appended a shutdown command to shell configuration files. Disclosed via Nx's GitHub security advisory and postmortem and analysed by Wiz Research.

Impact as stated

Per Wiz: over a thousand valid GitHub tokens, dozens of valid cloud credentials and NPM tokens, and roughly twenty thousand additional files leaked; a subsequent wave made over 5,500 private repositories public across 400+ users and organisations. Malware also attempted host lockout via a shutdown command appended to shell startup files.

Facts as stated by sources

Actor
Unknown (Unknown)
Category
Infrastructure abuse / supply chain
Models named
Claude, Gemini, Amazon Q
Model families
Claude (Anthropic), Gemini (Google), Other / unspecified
Agentic autonomy level
Tool-assisted
Guardrail bypass
Legitimate tool abuse
Attack lifecycle phases
Resource development, Initial access, Execution, Credential access, Exfiltration, Impact
Target sectors
not stated
Target countries
not stated
Organisations affected
400
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0053
MITRE ATT&CK
T1567.001

Mitigations as stated

  • Rotate exposed credentials and tokens; remove the malicious package versions.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Sources (3)

  1. S1ngularity - What Happened, How We Responded, What We Learned
    Nx · First-party disclosure · · archived copy
  2. Nx security advisory (GHSA-cxm3-wv7p-598c)
    Nx / GitHub · First-party disclosure · · archived copy
  3. s1ngularity: supply chain attack leaks secrets on GitHub
    Wiz · Vendor report · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "nx-s1ngularity-supply-chain". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/nx-s1ngularity-supply-chain.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction