The NX S1ingularity Attack: Secrets in Plain Sight cover art

The NX S1ingularity Attack: Secrets in Plain Sight

The NX S1ingularity Attack: Secrets in Plain Sight

Listen for free

View show details

About this listen

Charlie Erkson and Mackenzie Jackson return with breaking news on one of the wildest supply chain compromises to date. The popular NX packages—with millions of weekly downloads—were hijacked, and attackers used an LLM-powered malware to crawl systems for secrets like GitHub and NPM tokens. Even stranger, instead of exfiltrating data to a private server, the stolen information was dumped into public GitHub repositories, exposing sensitive credentials for anyone to see.

In this episode of Bad Dependencies, the hosts unpack:

  • How the NX compromise happened and why it’s uniquely reckless.

  • The bizarre use of LLMs for system enumeration.

  • Why publishing secrets to public repos raises the stakes for everyone.

  • The remediation steps users must take if they were affected.

  • Broader implications for the future of software supply chain security.

Is this careless malware, or was the chaos intentional? Tune in for analysis, insights, and some grim humor as the hosts dissect a case study in just how bad things can get when package compromises go wrong.

No reviews yet
In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.