Nx Investigation Reveals GitHub Actions Workflow Exploit Led...
Blog post from Socket
In August 2025, a significant supply chain attack exploited a GitHub Actions workflow vulnerability in the Nx build system, leading to the theft of npm publishing tokens and raising alarms about CI/CD security practices. The attackers leveraged a sophisticated exploitation chain involving a bash injection vulnerability and the `pull_request_target` trigger, which ran workflows with elevated permissions, allowing them to publish malicious packages. The Nx team quickly responded by transitioning to npm's new Trusted Publishers mechanism, which uses ephemeral, workflow-specific credentials, eliminating the reliance on long-lived npm tokens. They also implemented additional security measures, including rebasing outdated branches, restricting external contributor permissions, and enhancing static code analysis. Throughout the incident, Nx maintained transparency, providing regular updates and collaborating with affected users, which set a high standard for incident response in the open-source community. This breach underscores the critical need for comprehensive security reviews and rapid adoption of advanced security practices to mitigate potential vulnerabilities in widely used software packages.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.