<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

1,000+ Developers Hit by AI-Powered Supply Chain Attack in Just 4 Hours

"Nx JavaScript build system hacked; AI-driven malware steals 20,000 files, exposing GitHub tokens and cloud credentials."
Content Team

Attackers compromised the popular Nx JavaScript build system on August 26, infecting over 1,000 developers and stealing 20,000 sensitive files in just four hours. The malware used AI tools like Claude Code and Gemini to hunt for GitHub tokens, SSH keys, and cryptocurrency wallets on victims' systems.

The attackers published malicious Nx packages at 10:32 PM UTC, then uploaded stolen data to public GitHub repositories with names like "singularity-repository-0" for easy collection. They also sabotaged victims' terminals to crash on startup, slowing incident response.

Despite quick takedown efforts, the damage was severe: over 1,000 valid GitHub tokens and dozens of cloud credentials were exposed. Shockingly, 90% of leaked GitHub tokens remain active, creating ongoing security risks for affected developers and their organizations.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo