Risky Bulletin Newsletter
August 29, 2025
Risky Bulletin: npm attack uses AI prompts to steal creds, crypto-wallet keys
Presented by

News Editor
A novel supply chain attack has hit the users of NX, a popular developer tool used to automate and optimize CI/CD pipelines.
The incident took place on Tuesday, after a threat actor compromised the npm token for one of the NX developers, and then released malicious updates for several NX tools to the npm package repository.
The new versions contained a malicious script that: