Loading…
Loading…
Written by Max Zeshut
Founder at Agentmelt · Last updated Jul 22, 2026
The August 26–27, 2025 supply-chain attack on the popular `nx` npm build system that installed a postinstall script explicitly designed to invoke the victim's local AI CLIs (Claude Code, Gemini CLI, Q CLI) with jailbroken prompts telling them to scan `~/.ssh`, `.env` files, cryptocurrency wallets, and GitHub tokens, then exfiltrate the results. Reports put losses at ~2,180 GitHub credentials and 20,000+ files in the first 48 hours. Named 's1ngularity' after the branding used by the attackers. Significance: the first mass-scale confirmed incident where an attacker weaponized *the victim's own AI agent* as the exfiltration engine, escalating the AI-agent supply-chain threat model from theoretical to operational. Anthropic, Google, and Amazon Q teams shipped mitigations shortly after; the Nx package was cleaned up within hours but the compromised versions had already been installed at scale.