NPM NX packets directed in the last worrying software supply attack




  • When a token with publication rights were stolen, multiple nx poisoned variants were released
  • Malware stole secrets and other important data
  • The attack lasted a few hours, but it could still be causing damage

Innumerable software developers, probably including those within Fortune 500 companies, were victims of a supply chain attack after NX, the open source construction system and the development tools kit, was compromised.

In an advertisement published in Github, NX said: “Malicious versions of NX and some support supplements” in NPM were published.

Leave a Comment

Your email address will not be published. Required fields are marked *