News · curated 19 Jul 2026
S1ngularity - What Happened, How We Responded, What We Learned
First reported nx.dev
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
The S1ngularity attack marks an emerging pattern where supply-chain malware weaponizes developers' locally installed AI assistants (Claude, Gemini) to aid reconnaissance and data theft, a threat vector defenders using AI dev tooling must account for.
Nx's postmortem details the S1ngularity incident of August 26, 2025, in which attackers exploited a GitHub Actions injection vulnerability to steal an NPM publishing token and push malicious versions of several Nx packages. The malware ran a post-install script that scanned systems for sensitive data, notably attempting to abuse locally installed AI CLI tools like Claude and Gemini, and exfiltrated results to public GitHub repositories via the GitHub CLI.