s1ngularity, also referred to as QUIETVAULT, is a malicious npm supply-chain campaign centered on trojanized Nx packages published to the Node.js ecosystem in August 2025. It is characterized as an AI-enabled software supply-chain threat in which attackers abused a compromised GitHub Actions workflow to obtain an npm publishing token, inject malicious code into widely used build-system packages, and distribute poisoned updates that appeared legitimate to developers and CI environments.
The malware’s primary function was credential and secret theft from developer workstations and build environments. Reported collection targets included GitHub tokens, npm credentials, SSH keys, API keys, cryptocurrency wallet material, and configuration data associated with AI CLI tooling. The operation also used stolen GitHub credentials to abuse repository permissions, including making private repositories public and exposing additional embedded secrets. s1ngularity has been described as one of the first documented cases in which attackers used AI CLI tools as a reconnaissance force multiplier rather than as the initial access vector.
Operationally, the campaign followed a package-tampering pattern later seen in related npm worm activity: malicious code was injected into package contents, a lifecycle script such as postinstall was added, and the package was republished so that code would execute automatically during dependency installation. This made both developer endpoints and CI/CD systems viable victims. The campaign targeted the JavaScript/npm ecosystem, specifically Nx consumers, and affected software development and build pipelines rather than a single vertical industry.
Researchers have assessed notable design and functional overlap between s1ngularity and later supply-chain worms such as Shai-Hulud, and some reporting treats the later activity as directly downstream of or evolutionarily linked to the earlier Nx compromise. s1ngularity is therefore significant both as a credential-harvesting infostealer in its own right and as an early exemplar of modern self-amplifying open-source ecosystem attacks that combine CI abuse, package compromise, and automation-assisted reconnaissance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware or attack family associated with large-scale software supply-chain attacks involving malicious library versions.
A named npm supply-chain malware campaign using injected bundle.js and postinstall hooks to execute malicious code during package installation.
A supply-chain compromise involving malicious Nx packages that steals developer credentials (e.g., GitHub tokens, npm creds, SSH/API keys, crypto wallet files) and uses stolen GitHub tokens to expose private repositories; also targets AI CLI tool configurations and uses AI CLI tools for reconnaissance.
Named supply-chain incident affecting the JavaScript/npm ecosystem (no further technical details provided in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.