malicious-actors-compromising-nx's-cicd-pipeline-and-publishing-tainted-npm-packages
malicious-actors-compromising-nx's-cicd-pipeline-and-publishing-tainted-npm-packages - organisation named in the AI Incident Database harm index.
What changed
Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply …
Timeline
- 21 Sept 2025Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data ExfiltrationIncident82%
PSF mapping
No PSF domains are mapped to this entity in the current public record.