Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Nx Investigation Reveals GitHub Actions Workflow Exploit Led...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
1,183
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

In August 2025, a significant supply chain attack exploited a GitHub Actions workflow vulnerability in the Nx build system, leading to the theft of npm publishing tokens and raising alarms about CI/CD security practices. The attackers leveraged a sophisticated exploitation chain involving a bash injection vulnerability and the `pull_request_target` trigger, which ran workflows with elevated permissions, allowing them to publish malicious packages. The Nx team quickly responded by transitioning to npm's new Trusted Publishers mechanism, which uses ephemeral, workflow-specific credentials, eliminating the reliance on long-lived npm tokens. They also implemented additional security measures, including rebasing outdated branches, restricting external contributor permissions, and enhancing static code analysis. Throughout the incident, Nx maintained transparency, providing regular updates and collaborating with affected users, which set a high standard for incident response in the open-source community. This breach underscores the critical need for comprehensive security reviews and rapid adoption of advanced security practices to mitigate potential vulnerabilities in widely used software packages.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.