GitHub, npm, Trivy, Checkmarx and Nx: Software Supply Chain Attacks Use Malicious npm Updates to Steal Credentials and Spread Malware

GitHub, npm, Trivy, Checkmarx and Nx: Software Supply Chain Attacks Use Malicious npm Updates to Steal Credentials and Spread Malware

Sophisticated Software Supply Chain Attacks Exploit Developer Tools for Credential Theft and Malware Distribution

A surge in software supply chain attacks is transforming trusted developer tools into vectors for credential theft and malware delivery. Campaigns linked to threat groups S1ngularity, Shai-Hulud, and TeamPCP demonstrate how compromised packages can infiltrate developer workstations, build systems, and cloud infrastructure through routine software updates bypassing direct attacks on individual organizations.

Instead of targeting victims one by one, attackers compromise widely used software by stealing publishing credentials, modifying legitimate components, and distributing malicious releases via established repositories. Automated installations then propagate the payload downstream, amplifying the impact of a single breach.

TeamPCP’s Operation reportedly compromised over 1,000 organizations, stealing 500,000+ credentials and exfiltrating 300GB of data, with global remediation costs estimated in the hundreds of millions of dollars.

Key Incidents and Tactics

  • S1ngularity Attack (August 26, 2025): Exploited a GitHub Actions injection flaw via a malicious pull request title, executing unauthorized shell commands in a workflow with elevated permissions. A stolen GitHub token enabled attackers to create a malicious branch, triggering a publishing workflow that extracted an npm publishing token to distribute infected Nx packages outside the official release pipeline. The malicious versions remained live for four hours, executing postinstall scripts to harvest sensitive data, including credentials and AI tool configurations (Claude, Gemini). Stolen data was exfiltrated to public GitHub repositories using credentials found on victim machines.

  • Shai-Hulud’s Self-Propagating Worm: Expanded the attack surface by searching for npm publishing tokens on compromised systems and using them to push infected updates to additional packages, creating a recurring distribution cycle.

  • TeamPCP’s Cross-Ecosystem Compromises: Targeted multiple tools, including Trivy, Checkmarx extensions, LiteLLM, and Telnyx. Malicious versions of LiteLLM (1.82.7 and 1.82.8) contained an information stealer that extracted secrets from files and process memory. The campaign highlighted cascading exposure risks: a compromised security tool in a build pipeline could reveal credentials used to publish other projects, enabling further malicious releases.

Response and Mitigation

Nx implemented OIDC-based Trusted Publishing, replacing npm tokens with short-lived credentials, and introduced release approval requirements and enhanced provenance checks to verify package origins. GitHub workflow permissions were also restricted to limit attack surfaces.

The incidents underscore the need for organizations to treat affected installations as credential and host compromises, not just dependency issues. While specific remediation steps were recommended such as isolating systems, removing malicious versions, and rotating exposed tokens the attacks reveal systemic vulnerabilities in software supply chains, where a single breach can propagate across ecosystems.

Source: https://cyberpress.org/npm-updates-deliver-malware/

GitHub cybersecurity rating report: https://www.rankiteo.com/company/github

npm, Inc. cybersecurity rating report: https://www.rankiteo.com/company/npm-inc-

Checkmarx cybersecurity rating report: https://www.rankiteo.com/company/checkmarx

Kedge Security cybersecurity rating report: https://www.rankiteo.com/company/kedge-security

Lynx Technology Partners (now Arcova) cybersecurity rating report: https://www.rankiteo.com/company/lynx-technology-partners

"id": "GITNPMCHEKEDLYN1790944654",
"linkid": "github, npm-inc-, checkmarx, kedge-security, lynx-technology-partners",
"type": "Cyber Attack",
"date": "8/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,000+ organizations',
                        'industry': 'Technology',
                        'name': 'Nx',
                        'type': 'Software Development Tool'},
                       {'industry': 'Technology',
                        'name': 'LiteLLM',
                        'type': 'AI/LLM Tool'},
                       {'industry': 'Cybersecurity',
                        'name': 'Trivy',
                        'type': 'Security Tool'},
                       {'industry': 'Cybersecurity',
                        'name': 'Checkmarx extensions',
                        'type': 'Security Tool'},
                       {'industry': 'Technology',
                        'name': 'Telnyx',
                        'type': 'Communication API'}],
 'attack_vector': ['Compromised publishing credentials',
                   'Malicious pull requests',
                   'Postinstall scripts',
                   'Self-propagating worm'],
 'data_breach': {'data_exfiltration': '300GB of data exfiltrated to public '
                                      'GitHub repositories',
                 'number_of_records_exposed': '500,000+ credentials',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (PII, secrets, configurations)',
                 'type_of_data_compromised': ['Credentials',
                                              'AI tool configurations',
                                              'Secrets from files and process '
                                              'memory']},
 'date_publicly_disclosed': '2025-08-26',
 'description': 'A surge in software supply chain attacks is transforming '
                'trusted developer tools into vectors for credential theft and '
                'malware delivery. Campaigns linked to threat groups '
                'S1ngularity, Shai-Hulud, and TeamPCP demonstrate how '
                'compromised packages can infiltrate developer workstations, '
                'build systems, and cloud infrastructure through routine '
                'software updates bypassing direct attacks on individual '
                'organizations. Attackers compromise widely used software by '
                'stealing publishing credentials, modifying legitimate '
                'components, and distributing malicious releases via '
                'established repositories, amplifying the impact of a single '
                'breach.',
 'impact': {'data_compromised': ['500,000+ credentials',
                                 '300GB of data',
                                 'AI tool configurations (Claude, Gemini)',
                                 'Secrets from files and process memory'],
            'financial_loss': 'Hundreds of millions of dollars (estimated)',
            'identity_theft_risk': 'High (PII exposure)',
            'operational_impact': 'Compromised installations treated as '
                                  'credential and host compromises',
            'systems_affected': ['Developer workstations',
                                 'Build systems',
                                 'Cloud infrastructure']},
 'initial_access_broker': {'entry_point': ['Malicious pull requests',
                                           'Compromised npm packages'],
                           'high_value_targets': ['npm publishing tokens',
                                                  'GitHub tokens']},
 'lessons_learned': 'The incidents underscore the need for organizations to '
                    'treat affected installations as credential and host '
                    'compromises, not just dependency issues. Systemic '
                    'vulnerabilities in software supply chains can propagate '
                    'across ecosystems from a single breach.',
 'motivation': ['Credential theft',
                'Malware distribution',
                'Data exfiltration'],
 'post_incident_analysis': {'corrective_actions': ['OIDC-based Trusted '
                                                   'Publishing',
                                                   'Release approval '
                                                   'requirements',
                                                   'Enhanced provenance checks',
                                                   'Restricted workflow '
                                                   'permissions'],
                            'root_causes': ['Stolen publishing credentials',
                                            'GitHub Actions injection flaw',
                                            'Lack of provenance checks',
                                            'Over-permissive workflows']},
 'ransomware': {'data_exfiltration': 'Yes'},
 'recommendations': ['Implement OIDC-based Trusted Publishing',
                     'Restrict GitHub workflow permissions',
                     'Enforce release approval requirements',
                     'Enhance provenance checks',
                     'Rotate exposed tokens',
                     'Isolate compromised systems'],
 'response': {'containment_measures': ['Isolating systems',
                                       'Removing malicious versions'],
              'remediation_measures': ['Rotating exposed tokens',
                                       'OIDC-based Trusted Publishing',
                                       'Release approval requirements',
                                       'Enhanced provenance checks']},
 'threat_actor': ['S1ngularity', 'Shai-Hulud', 'TeamPCP'],
 'title': 'Sophisticated Software Supply Chain Attacks Exploit Developer Tools '
          'for Credential Theft and Malware Distribution',
 'type': 'Software Supply Chain Attack',
 'vulnerability_exploited': ['GitHub Actions injection flaw',
                             'npm publishing token exposure']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.