NPM packages from Nx targeted in latest worrying software supply chain attack

NPM packages from Nx targeted in latest worrying software supply chain attack


  • When a token with publishing rights was stolen, multiple poisoned Nx variants were released
  • The malware stole secrets and other important data
  • The attack lasted a few hours, but could be causing damage still

Countless software developers, likely including those within Fortune 500 companies, were victims of a supply chain attack after Nx, the open source build system and development toolkit, was compromised.

In an announcement posted on GitHub, Nx said, “malicious versions of Nx and some supporting plugins were published” on NPM.

link

Leave a Reply

Your email address will not be published. Required fields are marked *