Story perspectives
Supply Chain Attack Exposes Thousands of Developer Credentials
8/29/2025
45 8
1 of 1
Story summary
- A supply chain attack on JavaScript developers using the Nx build system resulted in the theft of thousands of credentials.
- Hackers exploited a vulnerability to publish malicious Nx packages that collected sensitive data and uploaded it to GitHub repositories named "s1ngularity-repository."
- Identified on August 26, 2025, the attack impacted over 1,000 repositories and utilized AI tools for data exfiltration.
- Users of the compromised packages are advised to take immediate remediation steps.
