<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Hackers Launch First AI-Powered Supply Chain Attack on Popular Nx Build System

Cybercriminals execute "s1ngularity" attack on Nx JavaScript, exploiting AI for data theft, affecting over 4 million downloads.
Content Team

Cybercriminals executed a sophisticated supply chain attack called "s1ngularity" targeting the Nx JavaScript build system, which has over 4 million weekly downloads. On August 26, hackers exploited a workflow vulnerability to steal GitHub and NPM tokens, publishing eight malicious versions of Nx packages between 6:32-8:37 PM EDT.

The malware systematically harvested sensitive data from infected systems, including SSH keys, API tokens, and cryptocurrency wallet information. In a groundbreaking twist, attackers weaponized AI tools like Claude and Gemini to assist with reconnaissance and data theft—marking the first known case of AI being turned against developers in supply chain attacks.

Security firms discovered over 2,300 stolen secrets uploaded to more than 1,000 GitHub repositories. Half of these credentials remained valid when discovered, highlighting the urgent need for immediate revocation of compromised tokens.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo