S1ngularity is the name used for a multi-phase software supply-chain compromise of the Nx open-source build system and monorepo platform in August 2025. The activity was not conclusively attributed to a known threat actor. The attackers abused a compromised Nx maintainer credential and CI/CD publishing workflow to distribute malicious npm releases. The payload executed during package installation, harvested developer credentials, authentication tokens, cloud credentials, environment variables, and SSH keys, and used compromised GitHub accounts to publicly expose stolen data. The operation affected more than 2,000 GitHub accounts and approximately 7,200 repositories, including private repositories accessed with stolen credentials. The attackers also used locally available AI command-line tools on victim systems to automate reconnaissance and locate sensitive material. They attempted to conceal the compromise by deleting branches and workflow-run evidence. Stolen npm credentials enabled further package poisoning, and the activity is assessed as directly connected to the downstream Shai-Hulud self-propagating npm supply-chain campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A supply-chain campaign that compromised Nx publishing infrastructure, distributed malicious npm package updates, harvested credentials and SSH keys, and exfiltrated them through attacker-searchable public GitHub repositories. It notably used victim-side AI agents to locate sensitive files and credentials.
A campaign cited as demonstrating how compromise of a trusted component can expose downstream organizations at scale.
Supply-chain actor behind compromised npm packages used to steal tokens and keys, abuse GitHub-to-AWS OIDC trust, compromise CI/CD pipelines, exfiltrate data, and destroy production and cloud data.
Compromised the Nx build system by publishing malicious npm packages, stealing developer credentials, exfiltrating data, and leveraging AI CLI tools for enhanced reconnaissance.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.