s1ngularity / Nx
Developer workstations and CI
Malicious Nx releases ran an install-time payload on Linux and macOS. Researchers reported collection of GitHub and npm tokens, environment files, cloud credentials, and SSH keys; stolen GitHub tokens were later used to expose thousands of private repositories.
Read Wiz Research