OpsBuzz

Alert

Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident

On August 26–27, 2025 UTC , eight malicious Nx and Nx Powerpack releases were pushed to npm across two version lines and were live for ~5 hours 20 minutes

AI Security · MEDIUM
Source: Snyk Security BlogAug 27, 2025, 4:00 AMAI Securitymedium

Full content

On August 26–27, 2025 (UTC), eight malicious Nx and Nx Powerpack releases were pushed to npm across two version lines and were live for ~5 hours 20 minutes before removal.

Related alerts

Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident | OpsBuzz