Supply chain

Massive toll of Nx npm supply chain attack examined

(Credit: Araki Illustrations – stock.adobe.com)

BleepingComputer reports more than 2,000 accounts and 7,200 repositories on GitHub have been compromised across three phases of the s1ngularity npm supply chain intrusion against open source codebase management platform Nx.

Malicious Nx packages uploaded to npm during the attack's initial phase from August 26 to 27 exposed more than 2,000 secrets and 20,000 files, while the second phase from August 28 to 29 involving leaked GitHub tokens impacted 480 accounts and 6,700 private repositories, according to an analysis by Wiz researchers.

Meanwhile, the final phase on the last day of August aimed at a single organization was able to reveal 500 more private repositories. Further examination showed threat actors' utilization of a credential-stealing payload exploiting artificial intelligence platforms' command-line tools to enable modified prompts in every attack phase.

"These changes had a concrete impact on the success of the malware. The introduction of the phrase "penetration testing", for example, was concretely reflected in LLM refusals to engage in such activity," said Wiz researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds