Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware
Supply-chain worms in npm packages, including Nx, steal developer credentials and can enlist local AI coding tools.
Attackers have compromised npm packages, including Nx, and used trusted install paths to deploy credential-stealing malware. After an npm publishing token was stolen through a GitHub Actions workflow flaw, malicious Nx releases ran post-install scripts that searched for secrets and uploaded them to public GitHub repositories. S1ngularity prompted local AI coding tools such as Claude and Gemini to locate GitHub, npm, cloud, and SSH credentials. Shai-Hulud then republished packages with stolen maintainer tokens; Microsoft said August's ChainDrop campaign infected more than 400 npm packages, while authorities allege TeamPCP exposed over 500,000 credentials across more than 1,000 organizations.