AI-Driven "s1ngularity" Attack Compromises 2,180 GitHub Accounts
The “s1ngularity” attack has caused a significant breach affecting over 2,180 GitHub accounts and 7,200 repositories, exploiting vulnerabilities in the Nx open-source build system using AI-driven methods for credential theft. Attackers manipulated GitHub Actions to execute a malicious script that harvested sensitive data from Linux and macOS systems, ultimately uploaded to public repositories. In response, Nx has implemented stringent security measures, including token revocation and two-factor authentication. This incident highlights the growing threat of AI-enhanced cyberattacks, emphasizing the urgent need for robust security practices in open-source supply chains to mitigate future risks.