Attackers exploited a GitHub Actions workflow injection to steal Nx's npm token and publish malicious versions whose install script scanned systems for secrets, attempted to use locally installed AI CLIs such as Claude and Gemini to assist, and uploaded results to public GitHub repositories. Nx reports the packages were live about four hours and has since moved to trusted publishing and mandatory 2FA approval.
Why it matters
It is an early documented case of malware invoking a victim's own AI coding agents as reconnaissance tools.
Key facts
As stated in the sources, with where to find them.
- Eight versions of the nx package and eleven versions of seven related @nx packages (19 versions across 8 packages) were compromised; the malicious versions were live for about four hours.Affected versions; Immediate Containment
- The post-install script attempted to use locally installed AI tools such as Claude and Gemini.Malware behavior
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Sep 25, 2025
Aug 6, 2025
Apr 1, 2025
Feb 2, 2026
Jul 23, 2025
Sep 8, 2026