Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
On 26 August 2025 malicious versions of the Nx packages were published to npm carrying a post install script. Nx's own postmortem records that the script attempted to use locally installed AI tools to locate sensitive files, then published what it found to attacker created repositories in victims' own accounts. Reporting records the tools being invoked with their permission bypass flags.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0006
- Kind
- Exfiltration
- Jurisdiction
- Global
- Last verified
- Added
- The Nx postmortem states that on 26 August 2025 malicious versions of several Nx packages were published to npm.
- The postmortem records that the payload attempted to use local AI tools such as Claude and Gemini to locate sensitive files.
- Wiz reports the campaign weaponized installed AI command line tools by prompting them with dangerous flags that skip permission checks.
- Stolen credentials were written to attacker created repositories inside the victims' own accounts rather than sent to an external server.
- Nx states the malicious packages were active for four hours before complete removal from the registry.
Dimension by dimension
6 dimensions, each one stated, silent or open
Identity, Authorization, Human approval, Limits, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- The agent could not tell that the party prompting it was a post install script rather than its developer.Wiz, s1ngularity supply chain attack, secondary source, 27 August 2025.
- AuthorizationSilent
- The local agent held the developer's full filesystem reach and applied it to an attacker's instruction.Nx, s1ngularity postmortem, primary source, 5 September 2025.
- Human approvalSilent
- The permission prompt was the control, and the attack's entire method was the documented flag that skips it.Wiz, s1ngularity supply chain attack, secondary source, 27 August 2025.
- LimitsSilent
- Nothing capped what the agent could read or where its output could go.Wiz, s1ngularity supply chain attack, secondary source, 27 August 2025.
- RevocationStated
- The packages were removed from the registry, and the maintainers published a postmortem naming the affected versions.Nx, s1ngularity postmortem, primary source, 5 September 2025.
- AccountabilityStated
- The maintainers published a named postmortem describing the root cause in their own release workflow.Nx, s1ngularity postmortem, primary source, 5 September 2025.
Figures
Every number, with who measured it and when
- 4 hours
Time the malicious packages were live on the registry
Nx, s1ngularity postmortem, primary source, as of .
- 5,500 repositories
Private repositories made public in the second phase
Wiz, s1ngularity supply chain attack, secondary source, as of .
What it changes
For a team deploying an agent
Your developers' agents are now part of your attack surface, and the approval prompt is the control an attacker will aim at first. Treat any flag that skips agent permission checks as a production secret: forbid it in shell profiles, scripts and CI, and alert on its appearance. Then assume a local agent can read every credential on the machine, and stop keeping long lived tokens in developer filesystems.
Sources
What this record was verified against
- Nx, s1ngularity postmortemPrimary · 5 September 2025
- Wiz, s1ngularity supply chain attackSecondary · 27 August 2025
Related
Records that sit beside this one
Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine
United States · verified 15 September 2026
AWS security bulletin AWS-2025-015 states the malicious code was distributed with the extension but was unsuccessful in executing due to a syntax error.
A cloned MCP server silently copied every email agents sent through it
Global · verified 15 September 2026
The Register reports that a backdoored version added a blind copy of every message to an attacker controlled address.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0006 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), malware in the nx packages drove developers' own ai command line agents to hunt for secrets.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents
- MLA
- "Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0006-nx-s1ngularity-malware-drove-local-ai-coding-agents
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.