Malicious Nx Packages in 's1ngularity' Attack Leaked 2,349 GitHub, Cloud, and AI Credentials
29.08.2025
19112

A supply chain attack targeting Nx packages on npm has exposed thousands of credentials, putting GitHub, cloud services, and AI platforms at risk. The attack, dubbed 's1ngularity', was discovered on August 26, 2025, and involved malicious packages that exfiltrated sensitive data from developers' systems.
🚨 BREAKING: Nx Supply Chain Attack Leaks 2,349 Creds – GitHub, Cloud, AI at Risk
Hey developers and security pros, listen up! A serious supply chain attack hit the Nx ecosystem on npm, and it's bad news. Dubbed 's1ngularity', this attack occurred on August 26, 2025, and has already leaked a massive 2,349 credentials from unsuspecting users. We're talking GitHub tokens, cloud service keys, and even AI platform access – basically, a goldmine for hackers.
The malicious packages were very sneaky, masquerading as legitimate Nx tools to trick developers into installing them. Once inside, they exfiltrated secrets from environments, putting accounts on platforms like AWS, Azure, and various AI services at risk. This isn't just a small leak – it's a full-scale credential theft that could lead to unauthorized access, data breaches, and other chaos.
Key details: The attack was discovered by security researchers who flagged the packages on npm. They have since been taken down, but the damage is done. If you've been using Nx recently, check your dependencies and rotate those keys immediately. This serves as a brutal reminder that supply chain attacks are on the rise, and open-source ecosystems need tighter security measures.
- • Date of attack: August 26, 2025
- • Number of credentials leaked: 2,349
- • Platforms affected: GitHub, various cloud services (e.g., AWS, Azure), AI platforms
- • Attack method: Malicious npm packages impersonating Nx tools
- • Impact: Potential unauthorized access, data breaches, and further exploits
Stay vigilant, folks. Always vet your dependencies and keep an eye on security advisories. This 's1ngularity' mess shows that no one's safe in the dev world these days. 🔒💻
#supply chain attacks#hack#malware#credentials leakage#credentials
Got a topic? Write to ATLA WIRE on Telegram:t.me/atla_community

