NPM packages from NX targeted in recent worrying software supply chain attack


  • When a token with publishing rights was stolen, several poisoned NX variants were released
  • Malware stole secrets and other important data
  • The attack lasted a few hours but could still cause harm

Countless software developers, probably including those within the Fortune 500 companies, were victims of a supply chain attack after NX, Open Source Build system and the development tool set were compromised.

In a message sent on GitHub, NX said, “malicious versions of NX and some supporting plugins were published” at NPM.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top