# Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident

DevFeed: [Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident](<https://devfeed.tech/articles/weaponizing-ai-coding-agents-for-malware-in-the-nx-malicious-package-security-incident-8232.md>)

Original publisher: [Read original article](<https://snyk.io/blog/weaponizing-ai-coding-agents-for-malware-in-the-nx-malicious-package/>)

Author: Liran Tal

Published: 2025-08-27T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [npm](<https://devfeed.tech/topics/npm.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [amazon](<https://devfeed.tech/topics/amazon.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [google](<https://devfeed.tech/tags/google.md>), [incident](<https://devfeed.tech/tags/incident.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [popular](<https://devfeed.tech/tags/popular.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [typescript](<https://devfeed.tech/tags/typescript.md>)

## AI overview

In August 2025, eight malicious Nx and Nx Powerpack releases were published to npm and remained available for about five hours before removal. The malware abused local AI coding-agent CLIs, including Claude Code, Google's Gemini CLI, and Amazon's q, to search for sensitive files and exfiltrate credentials and other data to a public GitHub repository. The incident was traced to a compromised GitHub Actions workflow and npm publishing token.

## Source excerpt

On August 26-27, 2025 (UTC), eight malicious Nx and Nx Powerpack releases were pushed to npm across two version lines and were live for ~5 hours 20 minutes before removal.