Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 1210: Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Description: Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: Anthropic , Google and Amazon developed an AI system deployed by Malicious actors compromising Nx’s CI/CD pipeline and publishing tainted npm packages, which harmed Nx users and organizations installing compromised npm packages.
Alleged implicated AI systems: Nx (monorepo tool and plugins) , npm registry , Claude Code CLI , Google Gemini CLI , Amazon q CLI and GitHub

Incident Stats

Incident ID
1210
Report Count
2
Incident Date
2025-08-21
Editors
Daniel Atherton

Incident Reports

Reports Timeline

Incident OccurrenceWeaponizing AI Coding Agents for Malware in the Nx Malicious Package Security IncidentArtificial intelligence ushers in a golden age of hacking, experts say
Loading...
Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident

Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident

snyk.io

Loading...
Artificial intelligence ushers in a golden age of hacking, experts say

Artificial intelligence ushers in a golden age of hacking, experts say

washingtonpost.com

Loading...
Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident
snyk.io · 2025

On August 26--27, 2025 (UTC), eight malicious Nx and Nx Powerpack releases were pushed to npm across two version lines and were live for ~5 hours 20 minutes before removal. The attack also impacts the Nx Console VS Code extension.

September…

Loading...
Artificial intelligence ushers in a golden age of hacking, experts say
washingtonpost.com · 2025

LAS VEGAS --- While many business sectors are still weighing the pluses and minuses of generative AI, criminal hackers are jumping in with both feet.

They have figured out how to turn the artificial intelligence programs proliferating on mo…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
GitHub Copilot, Copyright Infringement and Open Source Licensing

GitHub Copilot, Copyright Infringement and Open Source Licensing

Jun 2021 · 5 reports
Loading...
DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

Jun 2022 · 4 reports
Loading...
Bad AI-Written Christmas Carols

Bad AI-Written Christmas Carols

Dec 2017 · 1 report
Previous IncidentNext Incident

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
GitHub Copilot, Copyright Infringement and Open Source Licensing

GitHub Copilot, Copyright Infringement and Open Source Licensing

Jun 2021 · 5 reports
Loading...
DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

Jun 2022 · 4 reports
Loading...
Bad AI-Written Christmas Carols

Bad AI-Written Christmas Carols

Dec 2017 · 1 report

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 1d52523