WorkThe story, in brief

s1ngularity: supply chain attack in Nx packages

An LLM-powered supply chain attack just hit npm. Here's why your AI dev tools are now a security vector.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A sophisticated supply chain attack exploited stolen npm credentials to inject malicious code that used LLMs to exfiltrate developer secrets. This signals a new class of AI-enabled threats targeting the infrastructure developers rely on—and exposes how AI tooling (Claude, Gemini, Q CLIs) can become attack surface in build pipelines.

The key facts

7 to know
  1. Attack vector: Malicious Nx packages with postinstall scripts using LLMs to scan filesystems for secrets

  2. Timeline: August 26, 2025, 6:32 PM EDT to 10:44 PM EDT (4+ hours exposure)

  3. Attack mechanism: LLM-powered credential exfiltration posted as encoded strings to attacker-controlled GitHub repos

  4. AI tools exploited: Claude Code CLI, Gemini CLI, Q CLI required for full payload execution

  5. Vercel impact: No confirmed compromised builds (required 4 specific conditions: Nx package install + GitHub CLI + GitHub token + AI CLI present)

  6. Scope: Affected Nx ecosystem packages removed from npm; Vercel purged build caches; small user cohort notified

  7. Defense implication: LLM CLI tools in build containers introduce new credential-theft surface area

Go to the source

Vercel Blogvercel.com

Publisher excerpt: Threat actors published modified versions of the Nx package and some of its supporting libraries to the npm registry with the goal of exfiltrating developer and service credentials. to check if your local or other CI environments are impacted.Builds on Vercel are safe from this vulnerability by…
Read original report
Back to today's editionMore work news

The wider picture

View all
Paper-cut illustration of an amber microchip with circuit paths extending into a row of data-center cabinets.
AI illustration by KeyNews
Work01

It’s Donald Trump Versus MAGA on Data Centers

Political fracture over data-center expansion reveals a disconnect between federal AI strategy and grassroots opposition—a workplace/policy story about who pays for the compute buildout and who resists it.

Wired AI
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work02

Daily AI usage in the U.S. has more than doubled in just six months

AI adoption has crossed from early-adopter to mainstream in the US workforce and daily life. This shift signals that practitioners can expect AI fluency to become a baseline job requirement, and employers need to rethink training, tooling, and team composition around an AI-native workforce.

The Decoder
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work03

Trump announces "AI Force" and plans for an "AI czar" as he pushes unchecked AI growth

Policy and regulatory direction matter to practitioners and enterprises. Trump's announced AI governance model—institutional elevation via a dedicated force, appointment of a czar, and explicit rejection of regulation—reshapes the operating environment for AI deployment, data-center buildout, and talent strategy over the next term.

The Decoder