The Nx s1ngularity Supply Chain Attack
Updated 5 Oct 2026 · Incident date 26 Aug 2025 · npm
nx and @nrwl/nx-* Powerpack packages - 8 malicious releases across two version lines, live ~5h20mtelemetry.jsThe nx npm package had eight malicious releases on 26 and 27 August 2025, from 20.9.0 to 21.8.0. They were live for about 5 hours 20 minutes. Each added a telemetry.js file and a postinstall hook that stole secrets.
The malware also ran the Claude, Gemini and Amazon q command line tools on the victim machine to help find files to steal.
What happened
An attacker published poisoned nx releases to npm using a stolen publishing token. StepSecurity lists the first malicious release, 21.5.0, at 10:32 PM UTC on 26 August 2025. Community members alerted the Nx team at 12:30 AM on 27 August. npm removed the versions at 02:44 AM and the Nx organization revoked the compromised account at 03:52 AM.
Each release added a postinstall script that runs node telemetry.js. The script exits at once on Windows. On other systems it collects GitHub tokens through gh auth token, npm tokens from ~/.npmrc, SSH private keys, .env files and cryptocurrency wallet files.
The script also ran locally installed AI tools with their safety checks off. It used --dangerously-skip-permissions for Claude, --yolo for Gemini and --trust-all-tools for q. A prompt told each tool to search the filesystem for configuration and environment files and write the paths to /tmp/inventory.txt.
The script then created a public GitHub repository named s1ngularity-repository in the victim account, using the stolen token. It triple base64 encoded the data and uploaded it as results.b64. It also appended sudo shutdown -h 0 to ~/.bashrc and ~/.zshrc, so a new terminal shut the machine down.
Snyk reports the root cause as a flawed GitHub Actions workflow added by pull request on 21 August 2025. A later commit on 24 August changed it to send the npm token to a webhook. StepSecurity names bash injection in a pull request title check and the pull_request_target trigger as the two flaws. The VS Code Nx Console extension was also affected through automatic version checks.
Affected versions
nx: 20.9.0, 20.10.0, 20.11.0, 20.12.0, 21.5.0, 21.6.0, 21.7.0, 21.8.0.@nx/devkit: 21.5.0 and 20.9.0.@nx/eslint,@nx/js,@nx/node,@nx/workspace: 21.5.0 and 20.9.0.@nx/enterprise-cloud: 3.2.0.- VS Code Nx Console 18.63.x to 18.65.x. StepSecurity lists 18.66.0 or later as the fix.
Snyk also lists @nx/key among the affected plugins.
Indicators of compromise
- File
telemetry.jsin an installed nx package and apostinstallscript that runs it. - Files
/tmp/inventory.txtand/tmp/inventory.txt.bak. - The line
sudo shutdown -h 0in~/.bashrcor~/.zshrc. - Public GitHub repositories named
s1ngularity-repositoryors1ngularity-repository-*that holdresults.b64. - Calls to
api.github.comduringnpm installandgh auth tokenruns bytelemetry.js. - Claude, Gemini or q runs in shell history with
--dangerously-skip-permissions,--yoloor--trust-all-tools.
How to check
List the nx versions in your project and compare them with the affected list. This command does not run any install script.
npm ls nx
Then check for the shutdown line and the inventory file.
grep -n "shutdown -h 0" ~/.bashrc ~/.zshrc
ls -l /tmp/inventory.txt*
Search your GitHub account for repositories whose names start with s1ngularity-repository.
Vigilance compares the version you trust with a new one. For nx, it will report the new telemetry.js file and the postinstall hook that runs shell commands.
What to do now
- Remove
node_modulesand clear the npm cache withnpm cache clean --force. - Reinstall nx at a clean version that is not on the affected list.
- Delete the
sudo shutdown -h 0line from~/.bashrcand~/.zshrc, and remove/tmp/inventory.txt. - Rotate all GitHub tokens, npm tokens, SSH keys and API keys. Move any wallet funds that the machine can reach.
- Check the GitHub audit log for new repositories and delete any
s1ngularity-repositoryrepositories. - Update Nx Console to 18.66.0 or later.
- Set
ignore-scripts=truein.npmrcand usenpm ci --ignore-scriptsin CI.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 36 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE telemetry.js It runs a command on its own when it is installed and reads saved passwords and access keys.
Frequently asked questions
Which nx versions were compromised in the s1ngularity attack?
Eight nx releases were malicious: 20.9.0, 20.10.0, 20.11.0, 20.12.0, 21.5.0, 21.6.0, 21.7.0 and 21.8.0. Several @nx plugin packages were also affected. They were live for about 5 hours 20 minutes on 26 and 27 August 2025.
How did the Nx malware use AI tools?
The telemetry.js script ran installed Claude, Gemini and q command line tools with permission checks turned off. It told them to search the filesystem for configuration and environment files and write the paths to /tmp/inventory.txt.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.