Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Nx s1ngularity Attack 2025: How a Stolen npm…
Breach analysis Incident: 26 Aug 2025

Nx s1ngularity Attack 2025: How a Stolen npm Token Turned a Build Tool into a Credential Stealer That Abused AI CLIs

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 8 min read
On this page

On 26 August 2025, attackers published malicious versions of Nx, a build system for JavaScript projects with around six million weekly installs, to the npm registry. They had stolen Nx's npm publishing token by exploiting a GitHub Actions workflow in the Nx repository. The infected packages ran a post-install script that searched developers' machines for secrets, including GitHub and npm tokens, SSH keys, cloud credentials and AI tool configuration, and even prompted locally installed AI command-line tools such as Claude, Gemini and Amazon Q, with safety-bypassing flags, to help find files. The results were uploaded to public repositories named "s1ngularity-repository" in each victim's own GitHub account. GitGuardian counted 2,349 distinct secrets from 1,079 such repositories, about half still valid. In a second phase on 28 and 29 August, an attacker used stolen GitHub tokens to make victims' private repositories public; Wiz counted more than 5,500 repositories from over 400 users and organisations. The malicious versions were available for about four to five hours.

Key takeaways

  • Attackers exploited a pull_request_target workflow in the Nx repository to steal Nx's npm publishing token.
  • Malicious Nx versions collected tokens, keys and credentials from developer machines and CI runners and pushed them to public GitHub repositories.
  • The malware prompted installed AI CLIs (Claude, Gemini, Amazon Q) with flags that skip permission checks, a first according to StepSecurity.
  • GitGuardian found 2,349 distinct secrets from 1,079 exfiltration repositories; Wiz saw more than 1,000 valid GitHub tokens.
  • The identity lesson: one long-lived publishing token reachable from CI let attackers ship malware to millions, and every stolen token then opened the next wave.

At a glance

OrganisationsNx (Nrwl) open source project; developers and CI pipelines that installed the malicious versions
WhenMalicious packages published 26 August 2025; second phase 28 to 29 August 2025
AttackerUnattributed
Entry pointA GitHub Actions injection flaw in a pull_request_target workflow, used to steal the Nx npm publishing token
Identities abusedNx's npm publishing token and a read/write GitHub workflow token; victims' GitHub tokens, npm tokens, SSH keys, cloud credentials and AI tool credentials
Impact2,349 secrets exfiltrated to public repositories (GitGuardian); over 5,500 private repositories made public in the second phase (Wiz)
CategoryNHI, Agentic AI and AI agents. Incident class: confirmed NHI breach (stolen publishing token used for a credential-stealing supply chain attack)

What happened

Nx's post-mortem explains the entry point. A workflow that validated pull request titles used the pull_request_target trigger, which runs with the target repository's permissions and secrets, and echoed the title unsanitised. The repository still had GitHub's old default of read/write permissions for workflow tokens, and the publish workflow could be triggered through the API. The attacker opened a pull request whose title contained shell commands, obtained a read/write GitHub token, pushed a branch with a malicious script in place of the CI script and triggered the publish workflow against it. "When the publish workflow ran the malicious script, it had access to our NPM_TOKEN and exfiltrated it," Nx wrote. With the token, the attacker published infected versions directly, bypassing the release pipeline.

The post-install script scanned for secrets and, according to Wiz, "leveraged AI command-line tools (including Claude, Gemini, and Q) to aid in their reconnaissance efforts," prompting them "with dangerous flags ( --dangerously-skip-permissions , --yolo , --trust-all-tools )". Results were double-base64 encoded and uploaded to a new public repository in the victim's GitHub account. GitGuardian analysed these repositories: "Out of these repositories, we detected that 1,079 of them contain at least a secret," representing "2,349 distinct secrets," mostly GitHub, npm, AWS and OpenAI credentials, and "Half of these secrets were valid at the time of writing." It also found that 33% of compromised systems had at least one AI command-line client installed, and that AI tools often refused the malicious requests.

Then came a second phase. "An attacker used the leaked GitHub tokens from phase one to make victim's private repositories public," Wiz reported, "with a total of over 5500 private repositories published publicly." Nx removed the token, npm removed the packages and revoked Nx's tokens, and GitHub took down exfiltration repositories. Nx has since moved to npm Trusted Publishers using OIDC, requires manual two-factor approval for releases and has disabled pipeline runs for all external contributors without approval. We cover a separate 2026 incident involving Nx Console in our GitHub internal repositories breach 2026 page.

Timeline

DateEvent
26 August 2025Malicious Nx versions are published to npm using the stolen token and removed after a few hours.
27 August 2025StepSecurity, Wiz and GitGuardian publish analyses.
28 August 2025Second phase: stolen GitHub tokens are used to make private repositories public.
29 August 2025The second-phase automation stops at about 2 a.m. UTC, according to Wiz.

How it happened: the identity attack path

  1. Workflow injection. A malicious pull request title ran commands in a pull_request_target workflow.
  2. Workflow token abused. A read/write GitHub token let the attacker push a branch and trigger the publish workflow.
  3. Publishing token stolen. The publish workflow exposed the npm token to the attacker's script.
  4. Malicious release. Infected Nx versions harvested secrets from developers and CI, using AI CLIs to help.
  5. Second wave. Stolen GitHub tokens were used to publish victims' private repositories.

Impact

  • Exfiltrated: 2,349 distinct secrets from 1,079 repositories, about half valid at the time (GitGuardian).
  • Private code exposed: over 5,500 private repositories from over 400 users and organisations made public (Wiz).
  • Scale: Nx has about six million weekly installs; the malicious versions were live for a few hours.

What this means for NHI governance

Every step of this attack ran on a non-human identity. A workflow token with more permissions than it needed let the attacker reach the publishing workflow. A long-lived npm token in that workflow let them publish as Nx. The malware then collected thousands of developer and CI tokens, and those tokens powered the second wave. Nx's own summary of its mistake is blunt: "if you gained access to our trusted environment (the Nx OSS repository), you were able to publish to NPM."

The fixes are identity fixes: read-only defaults for workflow tokens, no pull_request_target with secrets, OIDC-based trusted publishing instead of stored tokens, and fast revocation of anything leaked. The use of AI command-line tools adds a new concern: developer AI agents with broad file access are now part of the attack surface. See our CI/CD Pipeline Identity Security Guide and AI Coding Agents Security Guide.

Recommendations

  • Use trusted publishing instead of stored tokens. OIDC-based publishing removes the long-lived token to steal. See our NHI Authentication Guide.
  • Set workflow tokens to read-only by default. Check older repositories that still use read/write. See the CI/CD Pipeline Identity Security Guide.
  • Never interpolate untrusted input in workflows. Treat pull request titles and branch names as attacker-controlled.
  • Revoke leaked secrets quickly. Deleting an exfiltration repository does not revoke what it contained. See the Leaked Credential Response Playbook.
  • Restrict AI CLI permissions on developer machines. Avoid permission-bypassing modes and keep secrets out of plaintext files. See the AI Coding Agents Security Guide.

Frequently asked questions

What was the Nx s1ngularity attack?

In August 2025, attackers stole Nx's npm publishing token through a GitHub Actions flaw and published malicious Nx versions that stole developer credentials and uploaded them to public GitHub repositories named s1ngularity-repository.

How many credentials were leaked?

GitGuardian found 2,349 distinct secrets in 1,079 exfiltration repositories, about half still valid when analysed. Wiz reported over a thousand valid GitHub tokens.

How did the attack use AI tools?

The malware prompted installed AI command-line tools such as Claude, Gemini and Amazon Q, using flags that skip permission prompts, to help search the filesystem for secrets. AI tools sometimes refused.

GitHub Internal Repositories Breach 2026 · SpotBugs Token Leak 2025 · Shai-Hulud npm Campaign · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Publishing tokens and workflow tokens hold the keys to your users' machines. We help teams move to trusted publishing, tighten workflow permissions and respond fast when tokens leak. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org