The Nx s1ngularity Supply Chain Attack

Updated 5 Oct 2026 · Incident date 26 Aug 2025 · npm

Packagenx and @nrwl/nx-* Powerpack packages - 8 malicious releases across two version lines, live ~5h20m
Filetelemetry.js

The nx npm package had eight malicious releases on 26 and 27 August 2025, from 20.9.0 to 21.8.0. They were live for about 5 hours 20 minutes. Each added a telemetry.js file and a postinstall hook that stole secrets.

The malware also ran the Claude, Gemini and Amazon q command line tools on the victim machine to help find files to steal.

What happened

An attacker published poisoned nx releases to npm using a stolen publishing token. StepSecurity lists the first malicious release, 21.5.0, at 10:32 PM UTC on 26 August 2025. Community members alerted the Nx team at 12:30 AM on 27 August. npm removed the versions at 02:44 AM and the Nx organization revoked the compromised account at 03:52 AM.

Each release added a postinstall script that runs node telemetry.js. The script exits at once on Windows. On other systems it collects GitHub tokens through gh auth token, npm tokens from ~/.npmrc, SSH private keys, .env files and cryptocurrency wallet files.

The script also ran locally installed AI tools with their safety checks off. It used --dangerously-skip-permissions for Claude, --yolo for Gemini and --trust-all-tools for q. A prompt told each tool to search the filesystem for configuration and environment files and write the paths to /tmp/inventory.txt.

The script then created a public GitHub repository named s1ngularity-repository in the victim account, using the stolen token. It triple base64 encoded the data and uploaded it as results.b64. It also appended sudo shutdown -h 0 to ~/.bashrc and ~/.zshrc, so a new terminal shut the machine down.

Snyk reports the root cause as a flawed GitHub Actions workflow added by pull request on 21 August 2025. A later commit on 24 August changed it to send the npm token to a webhook. StepSecurity names bash injection in a pull request title check and the pull_request_target trigger as the two flaws. The VS Code Nx Console extension was also affected through automatic version checks.

Affected versions

Snyk also lists @nx/key among the affected plugins.

Indicators of compromise

How to check

List the nx versions in your project and compare them with the affected list. This command does not run any install script.

npm ls nx

Then check for the shutdown line and the inventory file.

grep -n "shutdown -h 0" ~/.bashrc ~/.zshrc
ls -l /tmp/inventory.txt*

Search your GitHub account for repositories whose names start with s1ngularity-repository.

Vigilance compares the version you trust with a new one. For nx, it will report the new telemetry.js file and the postinstall hook that runs shell commands.

What to do now

  1. Remove node_modules and clear the npm cache with npm cache clean --force.
  2. Reinstall nx at a clean version that is not on the affected list.
  3. Delete the sudo shutdown -h 0 line from ~/.bashrc and ~/.zshrc, and remove /tmp/inventory.txt.
  4. Rotate all GitHub tokens, npm tokens, SSH keys and API keys. Move any wallet funds that the machine can reach.
  5. Check the GitHub audit log for new repositories and delete any s1ngularity-repository repositories.
  6. Update Nx Console to 18.66.0 or later.
  7. Set ignore-scripts=true in .npmrc and use npm ci --ignore-scripts in CI.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old nx-prev --new nx-current
files scanned: 36 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   telemetry.js
           It runs a command on its own when it is installed and reads saved passwords and access keys.

Frequently asked questions

Which nx versions were compromised in the s1ngularity attack?

Eight nx releases were malicious: 20.9.0, 20.10.0, 20.11.0, 20.12.0, 21.5.0, 21.6.0, 21.7.0 and 21.8.0. Several @nx plugin packages were also affected. They were live for about 5 hours 20 minutes on 26 and 27 August 2025.

How did the Nx malware use AI tools?

The telemetry.js script ran installed Claude, Gemini and q command line tools with permission checks turned off. It told them to search the filesystem for configuration and environment files and write the paths to /tmp/inventory.txt.

Sources

  1. stepsecurity.io/blog/supply-chain-security-alert-popular-nx-build-system-package-compromised-with-data-stealing-malware
  2. snyk.io/blog/weaponizing-ai-coding-agents-for-malware-in-the-nx-malicious-package/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free