Attackers poisoned multiple open-source packages in separate supply-chain incidents, including malicious nx and related @nx npm releases and eight compromised Packagist packages. Nrwl said the Nx compromise began after attackers exploited a vulnerable pull_request_target GitHub Actions workflow in the nrwl/nx repository, stole an npm publishing token, and pushed tainted versions that ran a postinstall script. The malware searched local file systems, collected credentials and path data, exfiltrated information by creating GitHub repositories containing s1ngularity-repository in victims’ accounts, and altered shell startup files such as .zshrc and .bashrc to add a shutdown command that could prompt for a system password. Affected Nx versions included 20.9.0 through 20.12.0 and 21.5.0 through 21.8.0, while some Nx Console VSCode users were also exposed because versions 18.6.30 through 18.65.1 automatically installed nx@latest.
A separate campaign hit Packagist by hiding malicious logic in package.json instead of composer.json, targeting PHP projects that also invoke JavaScript tooling during install or build steps. Socket reported that the packages attempted to fetch a Linux binary from GitHub Releases, save it as /tmp/.sshd, mark it executable, and launch it in the background, creating a remote-code-execution path during dependency installation while suppressing errors and disabling TLS verification. The compromised versions were removed from Packagist, and the Nx packages were removed from npm after disclosure, but both incidents underscored how attackers are abusing CI/CD workflows and cross-ecosystem package metadata to distribute malware, steal credentials, and evade defenders focused on a single package manager.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Socket reported that the malicious Packagist versions were removed and warned that placing the payload in package.json could evade defenders focused only on Composer metadata. The same payload was also reportedly referenced across 777 GitHub files, including some GitHub Actions workflows, suggesting multiple execution paths.
A coordinated attack inserted malicious code into package.json files of eight Packagist packages, targeting PHP projects that also use JavaScript build tooling. The postinstall logic attempted to download a Linux binary from GitHub Releases, save it as /tmp/.sshd, mark it executable, and run it in the background.
Analysis of the incident noted that Nx Console versions 18.6.30 through 18.65.1 automatically installed nx@latest, which could trigger the malicious postinstall even in environments not otherwise using Nx directly. This expanded the understood exposure beyond standard npm consumers.
Nrwl published a security advisory describing the malicious npm releases, the GitHub Actions workflow root cause, affected versions, and indicators of compromise. The company advised users to inspect GitHub audit logs and local systems, rotate GitHub and npm tokens and other credentials, clear caches, and remove compromised versions from internal registries.
The malicious Nx and related package versions were removed from npm after the compromise was identified. Nrwl's advisory states the removals occurred on August 26-27, 2025.
Unauthorized malicious versions of nx and related @nx packages were published to npm, including affected nx versions 20.9.0 through 20.12.0 and 21.5.0 through 21.8.0. The packages contained a postinstall script that scanned local files, collected credentials and path data, exfiltrated information by creating GitHub repositories under victims' accounts, and modified shell startup files to add a shutdown command.
Attackers abused a bash injection flaw in a pull_request_target workflow with elevated permissions in the nrwl/nx repository, then triggered another workflow and stole an npm publishing token via a malicious commit and webhook. This compromise enabled unauthorized publication of malicious Nx packages to npm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcewiz.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.