On 26 August 2025, attackers published malicious versions of Nx, a build system for JavaScript projects with around six million weekly installs, to the npm registry. They had stolen Nx's npm publishing token by exploiting a GitHub Actions workflow in the Nx repository. The infected packages ran a post-install script that searched developers' machines for secrets, including GitHub and npm tokens, SSH keys, cloud credentials and AI tool configuration, and even prompted locally installed AI command-line tools such as Claude, Gemini and Amazon Q, with safety-bypassing flags, to help find files. The results were uploaded to public repositories named "s1ngularity-repository" in each victim's own GitHub account. GitGuardian counted 2,349 distinct secrets from 1,079 such repositories, about half still valid. In a second phase on 28 and 29 August, an attacker used stolen GitHub tokens to make victims' private repositories public; Wiz counted more than 5,500 repositories from over 400 users and organisations. The malicious versions were available for about four to five hours.
Key takeaways
- Attackers exploited a pull_request_target workflow in the Nx repository to steal Nx's npm publishing token.
- Malicious Nx versions collected tokens, keys and credentials from developer machines and CI runners and pushed them to public GitHub repositories.
- The malware prompted installed AI CLIs (Claude, Gemini, Amazon Q) with flags that skip permission checks, a first according to StepSecurity.
- GitGuardian found 2,349 distinct secrets from 1,079 exfiltration repositories; Wiz saw more than 1,000 valid GitHub tokens.
- The identity lesson: one long-lived publishing token reachable from CI let attackers ship malware to millions, and every stolen token then opened the next wave.
At a glance
| Organisations | Nx (Nrwl) open source project; developers and CI pipelines that installed the malicious versions |
|---|---|
| When | Malicious packages published 26 August 2025; second phase 28 to 29 August 2025 |
| Attacker | Unattributed |
| Entry point | A GitHub Actions injection flaw in a pull_request_target workflow, used to steal the Nx npm publishing token |
| Identities abused | Nx's npm publishing token and a read/write GitHub workflow token; victims' GitHub tokens, npm tokens, SSH keys, cloud credentials and AI tool credentials |
| Impact | 2,349 secrets exfiltrated to public repositories (GitGuardian); over 5,500 private repositories made public in the second phase (Wiz) |
| Category | NHI, Agentic AI and AI agents. Incident class: confirmed NHI breach (stolen publishing token used for a credential-stealing supply chain attack) |
What happened
Nx's post-mortem explains the entry point. A workflow that validated pull request titles used the pull_request_target trigger, which runs with the target repository's permissions and secrets, and echoed the title unsanitised. The repository still had GitHub's old default of read/write permissions for workflow tokens, and the publish workflow could be triggered through the API. The attacker opened a pull request whose title contained shell commands, obtained a read/write GitHub token, pushed a branch with a malicious script in place of the CI script and triggered the publish workflow against it. "When the publish workflow ran the malicious script, it had access to our NPM_TOKEN and exfiltrated it," Nx wrote. With the token, the attacker published infected versions directly, bypassing the release pipeline.
The post-install script scanned for secrets and, according to Wiz, "leveraged AI command-line tools (including Claude, Gemini, and Q) to aid in their reconnaissance efforts," prompting them "with dangerous flags ( --dangerously-skip-permissions , --yolo , --trust-all-tools )". Results were double-base64 encoded and uploaded to a new public repository in the victim's GitHub account. GitGuardian analysed these repositories: "Out of these repositories, we detected that 1,079 of them contain at least a secret," representing "2,349 distinct secrets," mostly GitHub, npm, AWS and OpenAI credentials, and "Half of these secrets were valid at the time of writing." It also found that 33% of compromised systems had at least one AI command-line client installed, and that AI tools often refused the malicious requests.
Then came a second phase. "An attacker used the leaked GitHub tokens from phase one to make victim's private repositories public," Wiz reported, "with a total of over 5500 private repositories published publicly." Nx removed the token, npm removed the packages and revoked Nx's tokens, and GitHub took down exfiltration repositories. Nx has since moved to npm Trusted Publishers using OIDC, requires manual two-factor approval for releases and has disabled pipeline runs for all external contributors without approval. We cover a separate 2026 incident involving Nx Console in our GitHub internal repositories breach 2026 page.
Timeline
| Date | Event |
|---|---|
| 26 August 2025 | Malicious Nx versions are published to npm using the stolen token and removed after a few hours. |
| 27 August 2025 | StepSecurity, Wiz and GitGuardian publish analyses. |
| 28 August 2025 | Second phase: stolen GitHub tokens are used to make private repositories public. |
| 29 August 2025 | The second-phase automation stops at about 2 a.m. UTC, according to Wiz. |
How it happened: the identity attack path
- Workflow injection. A malicious pull request title ran commands in a pull_request_target workflow.
- Workflow token abused. A read/write GitHub token let the attacker push a branch and trigger the publish workflow.
- Publishing token stolen. The publish workflow exposed the npm token to the attacker's script.
- Malicious release. Infected Nx versions harvested secrets from developers and CI, using AI CLIs to help.
- Second wave. Stolen GitHub tokens were used to publish victims' private repositories.
Impact
- Exfiltrated: 2,349 distinct secrets from 1,079 repositories, about half valid at the time (GitGuardian).
- Private code exposed: over 5,500 private repositories from over 400 users and organisations made public (Wiz).
- Scale: Nx has about six million weekly installs; the malicious versions were live for a few hours.
What this means for NHI governance
Every step of this attack ran on a non-human identity. A workflow token with more permissions than it needed let the attacker reach the publishing workflow. A long-lived npm token in that workflow let them publish as Nx. The malware then collected thousands of developer and CI tokens, and those tokens powered the second wave. Nx's own summary of its mistake is blunt: "if you gained access to our trusted environment (the Nx OSS repository), you were able to publish to NPM."
The fixes are identity fixes: read-only defaults for workflow tokens, no pull_request_target with secrets, OIDC-based trusted publishing instead of stored tokens, and fast revocation of anything leaked. The use of AI command-line tools adds a new concern: developer AI agents with broad file access are now part of the attack surface. See our CI/CD Pipeline Identity Security Guide and AI Coding Agents Security Guide.
Recommendations
- Use trusted publishing instead of stored tokens. OIDC-based publishing removes the long-lived token to steal. See our NHI Authentication Guide.
- Set workflow tokens to read-only by default. Check older repositories that still use read/write. See the CI/CD Pipeline Identity Security Guide.
- Never interpolate untrusted input in workflows. Treat pull request titles and branch names as attacker-controlled.
- Revoke leaked secrets quickly. Deleting an exfiltration repository does not revoke what it contained. See the Leaked Credential Response Playbook.
- Restrict AI CLI permissions on developer machines. Avoid permission-bypassing modes and keep secrets out of plaintext files. See the AI Coding Agents Security Guide.
Frequently asked questions
What was the Nx s1ngularity attack?
In August 2025, attackers stole Nx's npm publishing token through a GitHub Actions flaw and published malicious Nx versions that stole developer credentials and uploaded them to public GitHub repositories named s1ngularity-repository.
How many credentials were leaked?
GitGuardian found 2,349 distinct secrets in 1,079 exfiltration repositories, about half still valid when analysed. Wiz reported over a thousand valid GitHub tokens.
How did the attack use AI tools?
The malware prompted installed AI command-line tools such as Claude, Gemini and Amazon Q, using flags that skip permission prompts, to help search the filesystem for secrets. AI tools sometimes refused.
Related NHI Mgmt Group resources
GitHub Internal Repositories Breach 2026 · SpotBugs Token Leak 2025 · Shai-Hulud npm Campaign · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Publishing tokens and workflow tokens hold the keys to your users' machines. We help teams move to trusted publishing, tighten workflow permissions and respond fast when tokens leak. See our NHI and AI agent security training.
References
- StepSecurity: s1ngularity: Popular Nx Build System Package Compromised with Data-Stealing Malware (27 August 2025)
- Wiz: s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know (27 August 2025)
- GitGuardian: The Nx "s1ngularity" Attack: Inside the Credential Leak (27 August 2025)