Sev0AI security incidents, tracked

All incidents / Manipulated AI

s1ngularity: npm malware turned developers' AI coding tools against them

Nx (Nrwl), disclosed 26 Aug 2025. Manipulated AI Data exposed High

Malicious versions of the Nx build tool, which has millions of weekly downloads, ran a script that ordered any installed Claude, Gemini or Amazon Q command-line assistant to hunt for secrets on the victim's machine. Stolen tokens, SSH keys and wallets were posted to public GitHub repos, and a second wave used them to make thousands of private repositories public.

Disclosed
26 Aug 2025
Organization
Nx (Nrwl)
Vendor
Multiple models
Product
Claude Code, Gemini CLI, Amazon Q
Type of AI
Coding assistant
How it happened
Manipulated AI: Agent hijack
Harm
Data exposed
Data involved
Credentials, Source code
Reach
Ecosystem-wide
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://nx.dev/blog/s1ngularity-postmortem
  2. https://www.wiz.io/blog/s1ngularity-supply-chain-attack
  3. https://thehackernews.com/2025/08/malicious-nx-packages-in-s1ngularity.html

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "s1ngularity: npm malware turned developers' AI coding tools against them", https://sev0.fyi/incidents/2025-08-26-nx-s1ngularity-ai-cli-malware/