AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

AI Incident Database · article · Aug 27, 2025 · UTC

Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.

Read original source ↗ Open in workspace

recordType
incident-report
evidenceStatus
reported
region
Global

Reported occurrence date: 2025-08-21T00:00:00.000Z

Evidence & attribution

AI Incident Database, Responsible AI Collaborative; McGregor (2021), Preventing Repeated Real World AI Failures by Cataloging Incidents. Incident-specific contributor credits are available at each citation link. Metadata adapted; article text excluded.

License: CC BY-SA 4.0

First collected: 2026-09-19T22:50:59.123Z. This is not the publication date.

Observed changes

AIIC observation times, not verified publisher revision times. Up to eight recent revisions.

2026-09-20T23:22:28.549Z

  • publishedAt: Not provided2025-08-27T00:00:00.000Z