The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory following the discovery of a widespread supply chain attack targeting the npm package ecosystem, known as the Shai-Hulud intrusion. Security researchers from StepSecurity identified that over 500 npm packages were compromised with self-replicating malware, significantly increasing the risk to organizations relying on open-source dependencies. The attack involved the injection of malicious code into popular packages, including the Nx build system and its related plugins, which are widely used for managing monorepos and automating development workflows. The malicious code, developed using a large language model according to Palo Alto Networks, was designed to execute immediately after package installation via a post-install hook, specifically targeting non-Windows systems. Once executed, the malware, named telemetry.js, collected sensitive host information, cryptocurrency wallets, and development credentials from affected developer machines. The stolen data was then triple-base64 encoded and exfiltrated to a public GitHub repository created using compromised GitHub tokens, under the name s1ngularity-repository. In addition to data theft, the malware attempted to disrupt developer operations by causing new terminal sessions to trigger immediate system shutdowns, resulting in denial-of-service conditions. CISA has recommended that all organizations using npm packages conduct immediate dependency reviews and thoroughly examine cached versions of affected dependencies to prevent further compromise. GitHub responded by removing the more than 500 impacted packages and implementing a ban on new uploads containing Shai-Hulud indicators of compromise. Security teams are also advised to rotate developer account credentials and enforce phishing-resistant multi-factor authentication to mitigate the risk of further account takeovers. The affected Nx packages include nx/devkit, nx/enterprise, nx/eslint, nx/js, nx/key, nx/node, and nx/workspace, with specific versions listed as vulnerable. The attack highlights the growing sophistication of supply chain threats, particularly those leveraging AI-generated code to evade detection and maximize impact. Organizations are urged to remain vigilant, update their security controls, and monitor for signs of compromise related to the Shai-Hulud malware. The incident underscores the critical importance of securing the software development lifecycle and maintaining robust monitoring of third-party dependencies. CISA's alert emphasizes the need for immediate action to prevent further exploitation and data loss. The coordinated response from security vendors, government agencies, and the open-source community demonstrates the seriousness of the threat and the necessity for ongoing vigilance in the face of evolving supply chain attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting linked the compromise to the 'Shai-Hulud' attack and stated that roughly 800 private repositories had been made public, showing broader downstream impact from the stolen credentials and package compromise.
U.S. cybersecurity authorities and CIS published advisories warning that the Nx package issue represented an extensive supply-chain compromise and urged organizations to immediately check dependencies, rotate exposed credentials, and assess affected environments.
A supply-chain compromise involving the Nx build system package enabled sensitive data exfiltration from developer and CI/CD environments, including tokens and other secrets that could be used to access source code repositories.
3 references tracked. Mallory keeps watching after this page renders.
securitysenses.com
Open sourcescworld.com
Open sourcecisecurity.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.