Opening Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools on Rogue Agent Watch.

Confirmed · Primary sourcing · AI significant · Critical severity.

On 2025-08-26 attackers exploited a flawed GitHub Actions workflow in the Nx build tool to publish malicious versions of nx and related npm packages. A postinstall script scanned victim machines for secrets and, notably, weaponised locally installed AI CLI tools (Claude, Gemini, Amazon Q) as file-search agents to locate sensitive files, then exfiltrated stolen data to attacker-created public GitHub repositories and appended a shutdown command to shell configuration files. Disclosed via Nx's GitHub security advisory and postmortem and analysed by Wiz Research.

Data: Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, CC BY-SA 4.0.