InfoAttack2025-08-26
ATTACK: Malicious Nx Packages Steal Developer and Service Credentials
Attackers exploited a GitHub Actions injection weakness, stole an npm publishing token and released malicious Nx packages designed to search systems for credentials.
Teams building internal Supply Chain and AI applications should pin package versions, protect publishing tokens and monitor build environments for credential access.
More details are available in the Nx postmortem.
L'angle Dataleo
The affected decision is whether build dependencies and release pipelines remain trusted after a Software Supply Chain compromise. Value requires locked versions, immediate secret rotation and reproducible builds; the principal failure mode is removing malicious packages while leaving exposed credentials and artifacts active.
