Attackers exploited a vulnerable Nx workflow on August 24, 2025. Two days later, malicious releases appeared on npm. Nx described the project’s reach as roughly six million weekly installs. The affected nx versions were removed slightly more than four hours after the first malicious publication, although two supporting packages remained available until the following morning. The official advisory does not state exactly how many developers were affected.
At first glance, this looked like another software supply-chain attack — the kind we now see every week. One detail made it different. The malware tried to recruit AI tools already installed on developers’ machines.