Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

s1ngularity: compromised Nx packages use AI coding agents to steal credentials

Malicious versions of the Nx build tool were published to npm with a post-install script that invoked Claude Code, Gemini CLI and Amazon Q on the developer's machine to locate wallets, tokens and SSH keys, then pushed them to public GitHub repositories.

Occurred 26 August 2025 · Disclosed 27 August 2025 · Record updated 13 September 2026

Impact

Wiz reported more than a thousand leaked GitHub tokens and thousands of secrets across affected developers, with follow-on repository exposures.

Our coverage

Sources

  1. github.comhttps://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7p-598c
  2. wiz.iohttps://www.wiz.io/blog/s1ngularity-supply-chain-attack
  3. semgrep.devhttps://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/