Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Nx build platform compromised by supply chain attack – How attackers collude with AI code assistants

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
1,256
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

In August 2025, several npm packages associated with the Nx build system were compromised by a malware that exploited AI code assistants to collect sensitive information, such as SSH keys and API tokens, and upload them to GitHub repositories. This incident highlights a new trend where attackers leverage the capabilities of AI assistants like Claude, Gemini, and Amazon Q to autonomously search for sensitive data without implementing their own search logic. The malicious packages, which included a script called "telemetry.js" executed post-installation, were swiftly removed from npm following their discovery by vigilant GitHub users and project maintainers. The attackers took advantage of a compromised npm token with publish rights, a known vector in software supply chain attacks, and utilized AI assistants' "hands-free" mode to bypass permission requirements. Although some AI models, like Claude Code, refused to execute the malicious requests, the incident underscores the potential for abuse when these models are misaligned, as well as the importance of prompt detection and response in mitigating such threats.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.