Npm Supply-Chain Attacks Steal Developer and Cloud Credentials
Attackers poisoned npm updates, including Nx, to steal developer and cloud credentials and enlist local AI tools.
Reports describe npm supply-chain attacks in which trusted updates, including Nx, ran post-install scripts that stole developer tokens, SSH keys, and cloud secrets and exfiltrated them to public GitHub repositories. Sources disagree on the initial Nx compromise: GBHackers says an npm publishing token was stolen through a GitHub Actions workflow flaw, while a ReversingLabs summary says attackers used a crafted pull request in August 2025 to replace a CI script and publish the malicious packages. S1ngularity prompted local AI coding tools to locate credentials—Claude and Gemini, according to GBHackers—and Shai-Hulud then reused stolen npm tokens to publish more malicious releases. Microsoft, cited only by GBHackers, said August's ChainDrop campaign infected more than 400 npm packages with a Mini Shai-Hulud variant; ReversingLabs does not mention ChainDrop. On TeamPCP, GBHackers says authorities allege more than 500,000 credentials were exposed across more than 1,000 organizations and that two Australian men were charged, while ReversingLabs says an unrotated Trivy token was used on March 19, 2026, to poison CI/CD tags and distribute CanisterWorm to more than 60 npm packages, with Checkmarx, LiteLLM, and Telnyx also affected.
- Malicious Nx npm releases ran post-install scripts that harvested tokens, SSH keys, and cloud secrets and uploaded them to public GitHub repositories.
- Sources differ on initial access: GBHackers says an npm publishing token was stolen via a GitHub Actions workflow flaw; ReversingLabs says an August 2025 crafted pull request replaced a CI script before malicious Nx packages were published.
- S1ngularity prompted local AI coding tools to find credentials; GBHackers names Claude and Gemini and GitHub, npm, cloud, and SSH secrets.
- Shai-Hulud reused stolen npm maintainer or publishing tokens to republish further malicious package versions.
- Microsoft, cited only by GBHackers, said August's ChainDrop campaign infected more than 400 npm packages with a Mini Shai-Hulud variant.
- GBHackers says authorities allege TeamPCP exposed over 500,000 credentials across more than 1,000 organizations and that two Australian men were charged.
- ReversingLabs says TeamPCP used an unrotated Trivy token on March 19, 2026, to poison CI/CD version tags and spread CanisterWorm to more than 60 npm packages, with Checkmarx, LiteLLM, and Telnyx also affected.
Coverage timelineoldest first · each row is one article
- · 10h agoHackers Are Turning Trusted Software Updates Into Credential-Stealing Malware
GBHackers· 76
Supply-chain worms in npm packages, including Nx, steal developer credentials and can enlist local AI coding tools.
- · 7h agoHackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials
Cyber Security News· 58
ReversingLabs traces S1ngularity, Shai-Hulud, and TeamPCP campaigns that poisoned npm updates to steal developer and cloud credentials.