s1ngularity: supply chain attack in Nx packages
A sophisticated supply chain attack exploited stolen npm credentials to inject malicious code that used LLMs to exfiltrate developer secrets. This signals a new class of AI-enabled threats targeting the infrastructure developers rely on—and exposes how AI tooling (Claude, Gemini, Q CLIs) can become attack surface in build pipelines.
Why it ranks · · Attack vector: Malicious Nx packages with postinstall scripts using LLMs to scan filesystems for secrets · 2025-08-27
Read full story