s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know
wiz.io | incident | #ai-security | #supply-chain | #secrets | #github-actions | #npm | #nx | #wiz-research | #s1ngularity
Summary
Wiz's initial analysis of s1ngularity: malicious Nx npm versions harvested wallets, tokens and SSH keys and abused local AI CLIs for recon; a second phase exposed 5,500+ private repositories.
- Published
- Collected
Skip to content