IncidentsMalware used developers' own AI agents to hunt for their secrets
The compromised Nx packages did not carry a credential scanner. They asked Claude Code, Gemini and Amazon Q to write one on the spot.
29 Aug 2025
Malicious versions of the Nx build tool were published to npm with a post-install script that invoked Claude Code, Gemini CLI and Amazon Q on the developer's machine to locate wallets, tokens and SSH keys, then pushed them to public GitHub repositories.
Occurred 26 August 2025 · Disclosed 27 August 2025 · Record updated 13 September 2026
Wiz reported more than a thousand leaked GitHub tokens and thousands of secrets across affected developers, with follow-on repository exposures.
IncidentsThe compromised Nx packages did not carry a credential scanner. They asked Claude Code, Gemini and Amazon Q to write one on the spot.
29 Aug 2025