This repository contains a base64-encoded dump of sensitive data wallet files, API keys, .npmrc credentials, environment variables, and more harvested directly from developers’ file systems.
Key Takeaways
1. Malware in the NX build tool steals credentials and creates GitHub repos.
2. Targets Claude and Gemini CLIs for advanced data exfiltration.
3. Delete suspicious repos, update NX, and rotate secrets urgently.
Semgrep reports that attackers leveraged the NX post-install hook via a file named telemetry.js to execute malicious code immediately after package installation.
The malware first collects environment variables and attempts to locate a GitHub authentication token via the GitHub CLI. Armed with credentials, it then creates a public repository such as s1ngularity-repository-0 and commits the stolen data in results.b64.
What makes this campaign particularly novel is its integration with Claude Code CLI or Gemini CLI. If either AI-powered CLI is present, the malware issues a carefully crafted prompt to conduct fingerprintable filesystem scans:
This AI-driven approach offloads the bulk of signature-based filesystem enumeration to the LLM, complicating traditional malware detection.
Developers using any impacted versions should immediately run:
or inspect lockfiles for vulnerable dependencies.
As the incident unfolds, organizations are urged to monitor repository creations and enforce strict post-installation auditing.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.
The post NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets appeared first on Cyber Security News.
Developer Behaviour Interactive has said the name Dead by Daylight players have waited 10 long…
A sophisticated software supply chain attack has successfully compromised the Laravel-Lang ecosystem, impacting hundreds of…
A sophisticated software supply chain attack has successfully compromised the Laravel-Lang ecosystem, impacting hundreds of…
Financially motivated threat actors are increasingly targeting software developers by impersonating popular AI coding assistants.…
Resident Evil director Zach Cregger has seen the calls for his movie to stick closer…
Workday has beaten analyst expectations in its first quarter results for Fiscal 2027. Revenue rose…
This website uses cookies.