s1ngularity: npm malware turned developers' AI coding tools against them
Malicious versions of the Nx build tool, which has millions of weekly downloads, ran a script that ordered any installed Claude, Gemini or Amazon Q command-line assistant to hunt for secrets on the victim's machine. Stolen tokens, SSH keys and wallets were posted to public GitHub repos, and a second wave used them to make thousands of private repositories public.
- Disclosed
- 26 Aug 2025
- Organization
- Nx (Nrwl)
- Vendor
- Multiple models
- Product
- Claude Code, Gemini CLI, Amazon Q
- Type of AI
- Coding assistant
- How it happened
- Manipulated AI: Agent hijack
- Harm
- Data exposed
- Data involved
- Credentials, Source code
- Reach
- Ecosystem-wide
- Severity
- High
- Model at fault
- No
- Status
- Confirmed