Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets

NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets

Posted on August 28, 2025August 28, 2025 By CWS

Over 1,400 builders found at present {that a} malicious post-install script within the fashionable NX construct equipment silently created a repository named s1ngularity-repository of their GitHub accounts. 

This repository incorporates a base64-encoded dump of delicate information pockets information, API keys, .npmrc credentials, setting variables, and extra harvested immediately from builders’ file programs.

Key Takeaways1. Malware within the NX construct device steals credentials and creates GitHub repos.2. Targets Claude and Gemini CLIs for superior information exfiltration.3. Delete suspicious repos, replace NX, and rotate secrets and techniques urgently.

AI-Assisted Knowledge Exfiltration

Semgrep stories that attackers leveraged the NX post-install hook through a file named telemetry.js to execute malicious code instantly after package deal set up. 

The malware first collects setting variables and makes an attempt to find a GitHub authentication token through the GitHub CLI. Armed with credentials, it then creates a public repository comparable to s1ngularity-repository-0 and commits the stolen information in outcomes.b64.

What makes this marketing campaign notably novel is its integration with Claude Code CLI or Gemini CLI. If both AI-powered CLI is current, the malware points a rigorously crafted immediate to conduct fingerprintable filesystem scans:

This AI-driven method offloads the majority of signature-based filesystem enumeration to the LLM, complicating conventional malware detection.

Affected NX Variations and Mitigations

@nx/devkit 21.5.0, 20.9.0

@nx/enterprise-cloud 3.2.0

@nx/eslint 21.5.0

@nx/key 3.2.0

@nx/node 21.5.0, 20.9.0

@nx/workspace 21.5.0, 20.9.0

@nx 20.9.0–20.12.0, 21.5.0–21.8.0

Builders utilizing any impacted variations ought to instantly run:

or examine lockfiles for susceptible dependencies. 

Seek for unauthorized repositories.

Delete any s1ngularity-repository* you discover.

Replace NX to protected model 21.4.1 (susceptible variations faraway from npm).

Rotate all uncovered secrets and techniques: GitHub tokens, npm credentials, SSH keys, setting variables.

Take away malicious shutdown directives in shell startup information (e.g., .bashrc).

Because the incident unfolds, organizations are urged to observe repository creations and implement strict post-installation auditing.

Discover this Story Attention-grabbing! Observe us on LinkedIn and X to Get Extra On the spot Updates.

Cyber Security News Tags:Build, Checks, Claude, Find, Gemini, Hacked, Malware, Secrets, Tool, Wallets

Post navigation

Previous Post: U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits
Next Post: Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials

Related Posts

TP-Link Router Zero-Day RCE Vulnerability Exploited Bypassing ASLR Protections TP-Link Router Zero-Day RCE Vulnerability Exploited Bypassing ASLR Protections Cyber Security News
Salesforce Releases Forensic Investigation Guide Following Chain of Attacks Salesforce Releases Forensic Investigation Guide Following Chain of Attacks Cyber Security News
Microsoft Security Keys May Require PIN After Recent Windows Updates Microsoft Security Keys May Require PIN After Recent Windows Updates Cyber Security News
Fortinet FortiWeb Instances Hacked with Webshells Following Public PoC Exploits Fortinet FortiWeb Instances Hacked with Webshells Following Public PoC Exploits Cyber Security News
Danabot Malware Resurfaced with Version 669 Following Operation Endgame Danabot Malware Resurfaced with Version 669 Following Operation Endgame Cyber Security News
‘The Gentlemen’ Ransomware Group with Dual-Extortion Strategy Encrypts and Exfiltrates Data ‘The Gentlemen’ Ransomware Group with Dual-Extortion Strategy Encrypts and Exfiltrates Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark