Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Pricing
Podcast Image

Bad Dependencies Podcast

The NX S1ingularity Attack: Secrets in Plain Sight

29 Aug 2025

Description

Charlie Erkson and Mackenzie Jackson return with breaking news on one of the wildest supply chain compromises to date. The popular NX packages—with millions of weekly downloads—were hijacked, and attackers used an LLM-powered malware to crawl systems for secrets like GitHub and NPM tokens. Even stranger, instead of exfiltrating data to a private server, the stolen information was dumped into public GitHub repositories, exposing sensitive credentials for anyone to see.In this episode of Bad Dependencies, the hosts unpack:How the NX compromise happened and why it’s uniquely reckless.The bizarre use of LLMs for system enumeration.Why publishing secrets to public repos raises the stakes for everyone.The remediation steps users must take if they were affected.Broader implications for the future of software supply chain security.Is this careless malware, or was the chaos intentional? Tune in for analysis, insights, and some grim humor as the hosts dissect a case study in just how bad things can get when package compromises go wrong.

Audio
Featured in this Episode

No persons identified in this episode.

Transcription

This episode hasn't been transcribed yet

Help us prioritize this episode for transcription by upvoting it.

0 upvotes
🗳️ Sign in to Upvote

Popular episodes get transcribed faster

Comments

There are no comments yet.

Please log in to write the first comment.