TF-MAL-js.s1ngularity
📛 Threat Title
Malware family: s1ngularity Stealer
Description
ThreatFox malware family `js.s1ngularity`. Printable name: s1ngularity Stealer.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:aitoolinsight.com
An AI-powered malware campaign named " s1ngularity " compromised 2,180 GitHub accounts and 7,200+ repositories. Learn how the attack worked, why AI was used, and what developers must do to secure their code.
-
web:blog.gitguardian.com
Breach explained The Nx " s1ngularity " Attack: Inside the Credential Leak On August 26, 2025, Nx, the popular build platform with millions of weekly downloads, was compromised with credential-harvesting malware . Using GitGuardian's monitoring data, we analyzed the exfiltrated credentials and reconstructed a fuller scope of exposure.
-
web:infosecbulletin.com
The telemetry.js malware is a credential stealer targeting Linux and macOS systems, which attempted to steal GitHub tokens, npm tokens, SSH keys, .env files, crypto wallets, and upload the secrets to public GitHub repositories named " s1ngularity -repository."
-
web:malpedia.caad.fkie.fraunhofer.de
s1ngularity Stealer Propose Change According to StepSecurity, this is a stealer deployed through a compromised Nx package, targeting system environment properties, cryptocurrency wallets, and development credentials. Data is exfiltrated to Github using stolen tokens.
-
web:nx.dev
Malicious Nx packages were published to npm via GitHub Actions exploit. Learn what happened and how we enhanced security measures.
-
web:thehackernews.com
Nx supply chain attack on Aug 26, 2025 leaked 2,349 secrets via npm packages, risking GitHub and cloud accounts.
-
web:www.microsoft.com
Trojan:JS/ S1ngularity was an advanced JavaScript supply chain attack that appeared in the last week of August 2025. It affected the distribution of the npm package of the Nx build system by releasing a malevolent version. The campaign's backbone was a malicious post-install script that runs during the installation of the package targeting the Linux and macOS development environments, Windows ...
-
web:www.rescana.com
The S1ngularity supply chain attack, as explored by Wiz in their detailed blog, illustrates how contemporary adversaries have evolved their techniques to infiltrate and destabilize software development processes. At its core, S1ngularity involves the unauthorized alteration of trusted software components during the build and update phases of the software development lifecycle. This alteration ...
-
web:www.stepsecurity.io
s1ngularity attack hijacked Nx package on npm to steal cryptocurrency wallets, GitHub/npm tokens, SSH keys, and environment secrets - the first documented case of malware weaponizing AI CLI tools for reconnaissance and data exfiltration.
-
web:www.wiz.io
s1ngularity : supply chain attack leaks secrets on GitHub: everything you need to know Detect and mitigate a critical supply chain compromise affecting the Nx NPM Package. Organizations should act urgently.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.