s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.s1ngularity

📛 Threat Title

Malware family: s1ngularity Stealer

Category: s1ngularity Stealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.s1ngularity`. Printable name: s1ngularity Stealer.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:aitoolinsight.com

    An AI-powered malware campaign named " s1ngularity " compromised 2,180 GitHub accounts and 7,200+ repositories. Learn how the attack worked, why AI was used, and what developers must do to secure their code.

  • web:blog.gitguardian.com

    Breach explained The Nx " s1ngularity " Attack: Inside the Credential Leak On August 26, 2025, Nx, the popular build platform with millions of weekly downloads, was compromised with credential-harvesting malware . Using GitGuardian's monitoring data, we analyzed the exfiltrated credentials and reconstructed a fuller scope of exposure.

  • web:infosecbulletin.com

    The telemetry.js malware is a credential stealer targeting Linux and macOS systems, which attempted to steal GitHub tokens, npm tokens, SSH keys, .env files, crypto wallets, and upload the secrets to public GitHub repositories named " s1ngularity -repository."

  • web:malpedia.caad.fkie.fraunhofer.de

    s1ngularity Stealer Propose Change According to StepSecurity, this is a stealer deployed through a compromised Nx package, targeting system environment properties, cryptocurrency wallets, and development credentials. Data is exfiltrated to Github using stolen tokens.

  • web:nx.dev

    Malicious Nx packages were published to npm via GitHub Actions exploit. Learn what happened and how we enhanced security measures.

  • web:thehackernews.com

    Nx supply chain attack on Aug 26, 2025 leaked 2,349 secrets via npm packages, risking GitHub and cloud accounts.

  • web:www.microsoft.com

    Trojan:JS/ S1ngularity was an advanced JavaScript supply chain attack that appeared in the last week of August 2025. It affected the distribution of the npm package of the Nx build system by releasing a malevolent version. The campaign's backbone was a malicious post-install script that runs during the installation of the package targeting the Linux and macOS development environments, Windows ...

  • web:www.rescana.com

    The S1ngularity supply chain attack, as explored by Wiz in their detailed blog, illustrates how contemporary adversaries have evolved their techniques to infiltrate and destabilize software development processes. At its core, S1ngularity involves the unauthorized alteration of trusted software components during the build and update phases of the software development lifecycle. This alteration ...

  • web:www.stepsecurity.io

    s1ngularity attack hijacked Nx package on npm to steal cryptocurrency wallets, GitHub/npm tokens, SSH keys, and environment secrets - the first documented case of malware weaponizing AI CLI tools for reconnaissance and data exfiltration.

  • web:www.wiz.io

    s1ngularity : supply chain attack leaks secrets on GitHub: everything you need to know Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.