NX NPM packages targeted in the latest supply chain attack in disturbing software


  • When a token with publication rights has been stolen, several poisoned NX variants have been published
  • Malware stole secrets and other important data
  • The attack lasted a few hours, but could still cause damage

Countless software developers, including probably those of fortune companies 500, have been victims of a supply chain attack after NX, the open source construction system and the development of the development tool, has been compromised.

In an announcement published on GitHub, NX said: “Malventy versions of NX and certain support plugins have been published” on NPM.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top