Malware & Info-Stealers 2025 Incident #45 CVE-2025-10894

Nx / s1ngularity

Estimated Financial Impact
2349 secrets leaked; 5500+ repos made public
Blast Radius
First attack weaponizing AI CLI tools

What Happened

Attackers stole an npm publishing token via a vulnerable GitHub Actions workflow and published malicious Nx versions with telemetry.js harvesting crypto wallets, GitHub/npm tokens, and SSH keys. First known attack to specifically weaponize AI CLI tools — it checked for Claude, Gemini, and Q developer tools on the system. Resulted in 2,349 secrets leaked and 5,500+ private repos made public.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects versions published without source changes

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTSSOURCE_MALFORMED_METADATA

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects versions published without source changes
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← Shai-Hulud npm worm @0xengine/xmlrpc →