s1ngularity is the name used for a 2025 software supply-chain intrusion centered on the Nx JavaScript build system and monorepo tooling ecosystem. The operation involved publication of malicious npm packages after compromise of maintainer credentials, followed by theft and abuse of developer and repository access tokens at scale. The campaign is associated with compromise of more than 2,000 GitHub accounts and roughly 7,200 repositories across multiple phases, including broad exposure of private repositories and secrets. The actor’s tradecraft focused on npm package poisoning and downstream abuse of stolen GitHub and npm credentials. Malicious package post-install behavior harvested secrets, environment variables, configuration data, SSH material, and developer credentials from victim environments, then abused the resulting access to expand compromise. Reported follow-on activity included creation of public repositories to leak stolen data and use of compromised tokens to access additional repositories. The intrusion chain has also been assessed as the precursor to the later Shai-Hulud npm worm campaign, in which stolen GitHub access enabled npm token theft and further package poisoning. A notable aspect of the operation was its targeting of developer workstations rather than only CI/CD infrastructure. Malware associated with the Nx compromise reportedly attempted to abuse locally installed AI command-line tools to improve reconnaissance and data discovery, and prompt modifications were observed across phases to increase effectiveness. This reflects an evolution in supply-chain attacks toward direct exploitation of developer tooling and local environments. Known activity attributed to s1ngularity is consistent with financially or opportunistically motivated credential and secret theft in the open-source software ecosystem, with emphasis on initial access through supply-chain compromise, credential theft, reconnaissance, exfiltration, and post-compromise expansion through stolen tokens. No high-confidence attribution to a specific nation state or source country is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain actor behind compromised npm packages used to steal tokens and keys, abuse GitHub-to-AWS OIDC trust, compromise CI/CD pipelines, exfiltrate data, and destroy production and cloud data.
Compromised the Nx build system by publishing malicious npm packages, stealing developer credentials, exfiltrating data, and leveraging AI CLI tools for enhanced reconnaissance.
A named activity cluster associated with an earlier supply-chain compromise that stole GitHub tokens, enabling subsequent npm token theft, repository exposure, and the downstream Shai-Hulud mass package poisoning campaign.
Conducted a multi-phase npm supply chain intrusion targeting Nx, uploading malicious packages to npm, exposing secrets and files, leaking GitHub tokens, compromising GitHub accounts and private repositories, and using a credential-stealing payload that exploited AI platform command-line tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.