Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious Nx Packages Used in Two Waves of Supply Chain Attack

## Cybersecurity: Supply Chain Attack on Nx Build System

Cybersecurity: Supply Chain Attack on Nx Build System

This week, the Nx build system package was targeted in a supply chain attack. An unauthorized actor obtained an Nx NPM token, enabling them to publish malicious versions of the package, which were designed to steal credentials and other sensitive data.

The maintainers of Nx have issued an alert regarding the attack, indicating that malicious versions of the Nx package, along with some associated plugin packages, were published to npm. These versions contained code that scanned file systems to collect credentials and then posted them to GitHub under users' accounts.

The attack, named "s1ngularity," originated from a vulnerable workflow introduced on Mon, Aug 21, 2023. This vulnerability allowed the injection of executable code. Although the workflow was quickly removed from the master branch upon discovery, the attacker exploited an outdated branch containing the vulnerable workflow.

On Tue, Aug 22, 2023, a social media post highlighted the injection exploit, prompting the Nx team to revert the workflow. Despite this, the flaw was exploited again on Thu, Aug 24, 2023. The team worked over the next two days to address these issues.

A subsequent attack wave was reported on Mon, Aug 28, 2023, involving the use of previously compromised GitHub tokens. These were used to change private repositories to public and rename them with a specific pattern.

This week, the Nx build system package was targeted in a supply chain attack.
Ryan Ellis · Thehackingpost

Nx is an open-source, technology-agnostic build platform widely used to manage large codebases, with over 3.5 million downloads weekly.

Following the reversion of the vulnerable workflow, a pull request was made on a fork of the nrwl/nx repository, targeting the outdated branch and exploiting a GITHUB_TOKEN with read/write permissions. The pull request was later deleted upon discovery.

The attack exploited the publish.yml workflow, which is responsible for publishing Nx packages and has access to the npm token through a GitHub Secret. To mitigate this, all NPM tokens with publishing permissions were revoked, and two-factor authentication was mandated for publishing.

The attack involved credential theft, scanning for credentials such as GitHub tokens, npm authentication keys, and SSH private keys. The compromised credentials were posted to public GitHub repositories.

Advertisement

One novel aspect involved the use of Large Language Model (LLM) clients to enumerate secrets on victims' machines, specifically targeting configuration files and authentication tokens associated with AI CLI tools.

The attack compromised 1,346 repositories, leaking 2,349 secrets, primarily GitHub OAuth keys and personal access tokens. The second attack wave, which began on Mon, Aug 28, 2023, affected over 400 users and organizations, resulting in more than 5,500 repositories being published publicly.

This incident underscores the evolving sophistication of supply chain attacks, particularly within popular ecosystems like Nx. It marks a significant case where AI tools were manipulated for malicious purposes, highlighting the need for heightened security measures in software development pipelines.

Based on reporting by devops.com.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories