Tell HN: 2nd wave of Nx attack: private GitHub repos are being made public

9 labordayruined 1 8/29/2025, 2:52:01 AM
It appears as though the attackers behind the Nx supply chain attack on Wednesday are now using leaked GitHub tokens to make private GitHub repositories public (and renaming them to s1ngularity-repository-XXXXX in the process). 7.2k repositories affected at time of writing.

https://xcancel.com/adnanthekhan/status/1961152614055207039

Comments (1)

fennec-posix ยท 4h ago
yeah, just did a search on github, ouch. This looks bad.

No comments yet