Skip to main content
VerifiedExfiltration

Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets

On 26 August 2025 malicious versions of the Nx packages were published to npm carrying a post install script. Nx's own postmortem records that the script attempted to use locally installed AI tools to locate sensitive files, then published what it found to attacker created repositories in victims' own accounts. Reporting records the tools being invoked with their permission bypass flags.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0006
Kind
Exfiltration
Jurisdiction
Global
Last verified
Added
  • The Nx postmortem states that on 26 August 2025 malicious versions of several Nx packages were published to npm.
  • The postmortem records that the payload attempted to use local AI tools such as Claude and Gemini to locate sensitive files.
  • Wiz reports the campaign weaponized installed AI command line tools by prompting them with dangerous flags that skip permission checks.
  • Stolen credentials were written to attacker created repositories inside the victims' own accounts rather than sent to an external server.
  • Nx states the malicious packages were active for four hours before complete removal from the registry.

Dimension by dimension

6 dimensions, each one stated, silent or open

Identity, Authorization, Human approval, Limits, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
The agent could not tell that the party prompting it was a post install script rather than its developer.Wiz, s1ngularity supply chain attack, secondary source, 27 August 2025.
AuthorizationSilent
The local agent held the developer's full filesystem reach and applied it to an attacker's instruction.Nx, s1ngularity postmortem, primary source, 5 September 2025.
Human approvalSilent
The permission prompt was the control, and the attack's entire method was the documented flag that skips it.Wiz, s1ngularity supply chain attack, secondary source, 27 August 2025.
LimitsSilent
Nothing capped what the agent could read or where its output could go.Wiz, s1ngularity supply chain attack, secondary source, 27 August 2025.
RevocationStated
The packages were removed from the registry, and the maintainers published a postmortem naming the affected versions.Nx, s1ngularity postmortem, primary source, 5 September 2025.
AccountabilityStated
The maintainers published a named postmortem describing the root cause in their own release workflow.Nx, s1ngularity postmortem, primary source, 5 September 2025.

Figures

Every number, with who measured it and when

  1. 4 hours

    Time the malicious packages were live on the registry

    Nx, s1ngularity postmortem, primary source, as of .

  2. 5,500 repositories

    Private repositories made public in the second phase

    Wiz, s1ngularity supply chain attack, secondary source, as of .

What it changes

For a team deploying an agent

Your developers' agents are now part of your attack surface, and the approval prompt is the control an attacker will aim at first. Treat any flag that skips agent permission checks as a production secret: forbid it in shell profiles, scripts and CI, and alert on its appearance. Then assume a local agent can read every credential on the machine, and stop keeping long lived tokens in developer filesystems.

Sources

What this record was verified against

  1. Nx, s1ngularity postmortemPrimary · 5 September 2025
  2. Wiz, s1ngularity supply chain attackSecondary · 27 August 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0006 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), malware in the nx packages drove developers' own ai command line agents to hunt for secrets.
APA
GAGE (Global Academy of Generative-AI Education). (2026). Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents
MLA
"Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents.
Chicago
GAGE (Global Academy of Generative-AI Education). "Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for Global and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.