Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration
Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.
- Date it happened
- 2025-08-21
- Organisation involved
- Malicious actors compromising Nx’s CI/CD pipeline and publishing tainted npm packages
- Product, system or model
- Nx (monorepo tool and plugins), npm registry, Claude Code CLI, Google Gemini CLI, Amazon q CLI, GitHub
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.