News · curated 19 Jul 2026

S1ngularity - What Happened, How We Responded, What We Learned

Coverage timeline

19 Jul 2026nx.dev

Single-source incident — first reported, latest, and curated coincide.

Why it matters

The S1ngularity attack marks an emerging pattern where supply-chain malware weaponizes developers' locally installed AI assistants (Claude, Gemini) to aid reconnaissance and data theft, a threat vector defenders using AI dev tooling must account for.

Nx's postmortem details the S1ngularity incident of August 26, 2025, in which attackers exploited a GitHub Actions injection vulnerability to steal an NPM publishing token and push malicious versions of several Nx packages. The malware ran a post-install script that scanned systems for sensitive data, notably attempting to abuse locally installed AI CLI tools like Claude and Gemini, and exfiltrated results to public GitHub repositories via the GitHub CLI.