Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

Claude Code CLI

Incidents implicated systems

Incident 12102 Report
Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

2025-08-21

Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Malicious actors compromising Nx’s CI/CD pipeline and publishing tainted npm packages

Incidents involved as Deployer
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

Anthropic

Incidents involved as Developer
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

Google

Incidents involved as Developer
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

Amazon

Incidents involved as Developer
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

Nx users and organizations installing compromised npm packages

Incidents Harmed By
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

Nx (monorepo tool and plugins)

Incidents implicated systems
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

npm registry

Incidents implicated systems
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

Google Gemini CLI

Incidents implicated systems
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

Amazon q CLI

Incidents implicated systems
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More
Entity

GitHub

Incidents implicated systems
  • Incident 1210
    2 Reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 1d52523