Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware
Supply-chain worms in npm packages, including Nx, steal developer credentials and can enlist local AI coding tools.
Attackers have compromised npm packages, including Nx, and used trusted install paths to deploy credential-stealing malware. After an npm publishing token was stolen through a GitHub Actions workflow flaw, malicious Nx releases ran post-install scripts that searched for secrets and uploaded them to public GitHub repositories. S1ngularity prompted local AI coding tools such as Claude and Gemini to locate GitHub, npm, cloud, and SSH credentials. Shai-Hulud then republished packages with stolen maintainer tokens; Microsoft said August's ChainDrop campaign infected more than 400 npm packages, while authorities allege TeamPCP exposed over 500,000 credentials across more than 1,000 organizations.
- Malicious Nx npm releases ran post-install scripts that exfiltrated secrets to GitHub.
- S1ngularity prompted local Claude and Gemini assistants to find credentials and tokens.
- Shai-Hulud reused stolen npm tokens to publish further malicious package versions.
- ChainDrop infected over 400 npm packages with a Mini Shai-Hulud variant.
- Authorities allege TeamPCP exposed over 500,000 credentials; two Australian men were charged.
Full article775 words · extracted from gbhackers.com · click to collapse
A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments.
Malicious Nx releases, published after attackers stole an npm publishing token through a GitHub Actions workflow flaw, ran post-install scripts that searched systems for sensitive data and uploaded it to attacker-controlled public GitHub repositories.
The compromised packages were available for roughly four hours, yet that was enough time to reach a significant number of developers.
What distinguished S1ngularity was its abuse of locally installed AI coding assistants.
The malware attempted to invoke tools such as Claude and Gemini and prompt them to locate GitHub credentials, npm tokens, cloud keys, SSH material and environment files.
In effect, attackers did not need to deploy a sophisticated custom discovery framework; they repurposed the victim’s own AI tooling to identify high-value secrets.
Nx described the incident as involving malicious packages that scanned devices, attempted to use local AI tools, and exfiltrated the findings through GitHub.
That tactic marked a major evolution in supply-chain compromise. The threat was not simply malicious code hidden in a dependency. It was malware that used trusted automation already present on the endpoint to accelerate credential discovery.
Shai-Hulud demonstrated the next stage: self-propagation. Rather than relying on a newly discovered software vulnerability, the worm stole npm publishing credentials from infected maintainers.
It used those credentials to publish malicious versions of additional packages. Every stolen token could therefore become the starting point for another compromise.

Reversinglabs identified that, the trend became impossible to ignore after the S1ngularity incident, which weaponized compromised Nx packages to turn victims’ local AI tools into automated reconnaissance assistants.
Credential-Stealing Malware
The model is especially dangerous because it exploits the trust relationship at the center of modern software delivery.
Developers routinely install dependencies, CI/CD systems automatically resolve package updates, and organizations often allow build tooling wide access to source repositories, registries and cloud services.
A compromised update can therefore arrive through a channel that security controls and users already regard as legitimate.

The attack family has continued to evolve. In August, the ChainDrop campaign infected more than 400 npm packages with a Mini Shai-Hulud variant delivered through a heavily obfuscated Bun-based JavaScript payload, according to Microsoft Threat Intelligence.
Elastic Security Labs reported that the worm harvested credentials by matching more than 300 patterns across developer credential stores, with notable targeting of AI-development tooling including Anthropic, Claude, Codex, Cursor, OpenAI and Gemini.
The risk increased further when TeamPCP allegedly released Mini Shai-Hulud publicly and encouraged other actors to use it.
Once a functional credential-stealing worm is available as a reusable framework, attackers no longer need the capability to engineer propagation, package discovery and token abuse from scratch. They can focus on access, targeting and evasion.
That democratization helps explain why supply-chain attacks are increasingly chained together.
A token compromised in one incident can be used to poison another package, steal another set of credentials and expand the blast radius again. The attack path is no longer linear; it is recursive.
Authorities allege TeamPCP’s operations potentially compromised more than 1,000 organizations worldwide, exposed over 500,000 credentials and authentication materials, and resulted in the theft of at least 300 GB of data.
Two Western Australian men were charged following a joint Australian Federal Police, Western Australia Police Force and FBI investigation.
The central lesson is that package publishing credentials must be treated as production-critical identities.
Long-lived npm tokens, overly permissive GitHub Actions workflows and unmanaged CI/CD secrets give attackers a direct route into trusted software distribution.
Organizations should shift package publishing to short-lived, workload-bound credentials through trusted publishing and OIDC; enforce least privilege on repository and registry tokens.
Require review and provenance checks for dependency updates; continuously monitor for unexpected preinstall and postinstall behavior; and rotate credentials completely after any compromise.
The S1ngularity, Shai-Hulud and ChainDrop campaigns show that a compromised software update is no longer merely a malware-delivery event.
It can become a credential-harvesting operation, a cloud-access incident and a launchpad for the next supply-chain attack all before defenders realize a trusted dependency has turned hostile.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.