ML Supply Chain Security advanced 8 min read 6 flashcards

Coding Agents as a Supply Chain Target

Why an installed coding agent is a credential-discovery engine an attacker can borrow, what the Nx s1ngularity compromise demonstrated about that, and how agent autonomy turns a per-machine compromise into a self-propagating one.

Developer workstations have always held secrets. What changed in 2025 is that they also hold a general-purpose tool, already authenticated, already permitted to read the filesystem, whose entire job is to find things and summarise them. An attacker who lands code on that machine no longer has to write a credential scanner. One is installed, and it is better than anything they would have written.

In late August 2025, malicious versions of the Nx build system, published to npm as versions 20.9.0 through 21.8.0, carried a telemetry.js post-install script that ran on Linux and macOS. Alongside conventional harvesting of GitHub and npm tokens, SSH keys, cloud credentials and wallet files, it checked for locally installed AI command-line tools, including Claude Code, Gemini CLI and Amazon Q, and invoked them to enumerate sensitive material on the host. The stolen data was exfiltrated to attacker-created public repositories inside the victims' own GitHub accounts (Wiz, 2025, s1ngularity supply chain attack). GitGuardian's analysis of the leaked repositories counted 2,349 distinct credentials from 1,079 compromised systems (GitGuardian, 2025).

What the agent added

Strip out the AI component and s1ngularity is an ordinary post-install credential stealer. The interesting part is what the agent contributed, which was generality.

A hand-written scanner matches patterns its author anticipated: .env, ~/.aws/credentials, id_rsa, a regex for AKIA. A model asked to find sensitive files on this machine reasons about the specific project in front of it. It reads the repository's own configuration, follows references, notices the unusual path where this team keeps its staging keys, and describes what it found in prose. The attacker ships one prompt instead of maintaining a signature list, and the capability improves whenever the victim upgrades their tooling.

The agent also arrives pre-authorised. Its file access was granted by the developer for legitimate work, so nothing in the malware's behaviour looks like privilege escalation. Endpoint tooling sees a known binary reading project files, which is what it does all day.

Autonomy makes compromise multiply

Self-propagation is the second escalation, and it does not need a model at all. The Shai-Hulud worm, first identified in npm packages in September 2025, stole credentials and then used the stolen npm tokens to publish itself into other packages maintained by the same victim, selecting targets by download count (CISA, 2025, Widespread Supply Chain Compromise Impacting npm Ecosystem; Krebs, 2025). A second wave in late November 2025 was substantially larger, with Datadog and Unit 42 documenting hundreds of affected packages and tens of thousands of attacker-created repositories (Datadog Security Labs, 2025, The Shai-Hulud 2.0 npm worm; Unit 42, 2025).

Put the two together and the shape of the risk is clear. A worm supplies propagation, an agent supplies discovery, and both run in a context where credentials with publishing rights sit on the same machine as the code being built.

When it breaks

"The agent is sandboxed" usually describes the wrong boundary. Many agent sandboxes constrain what the model may do while leaving the host's credential store and the developer's shell fully accessible to any other process, including the post-install script that just ran. The agent was not the attacker here; it was the victim's own tool, invoked by the attacker.

CI runners are workstations with better credentials and no user. The same post-install script runs in CI, where secrets are injected by design and no human is present to notice an unfamiliar process. Anything that treats build agents as lower risk than laptops has it backwards.

Detection assumes a signature and this has none. The malicious payload is a prompt. It is different on every run, it produces different outputs, and it leaves logs that look like ordinary agent transcripts. Detection has to move to the things that stay constant: unexpected network egress, credential reads outside a known pattern, and repository creation events.

Revocation is bounded by inventory. s1ngularity's victims needed to rotate every credential reachable from the affected machines, which is a set most organisations cannot enumerate. Short-lived, attested credentials shrink that set by construction; long-lived tokens in dotfiles make it unbounded.

Publishing rights on a developer machine are the amplifier. Both incidents turned a single compromised host into ecosystem-wide damage through publish tokens found locally. npm's move to OIDC-based trusted publishing and the removal of classic tokens in December 2025 attacks exactly this link (GitHub, 2025, npm security update).

References and further reading

Every source this page cites, in the order it cites them. All of them open in a new tab.

  1. Wiz, 2025, s1ngularity supply chain attack wiz.io
  2. GitGuardian, 2025 blog.gitguardian.com
  3. CISA, 2025, Widespread Supply Chain Compromise Impacting npm Ecosystem cisa.gov
  4. Krebs, 2025 krebsonsecurity.com
  5. Datadog Security Labs, 2025, The Shai-Hulud 2.0 npm worm securitylabs.datadoghq.com
  6. Unit 42, 2025 unit42.paloaltonetworks.com
  7. GitHub, 2025, npm security update github.blog
Check yourself

6 flashcards for this concept

Click a card to reveal the answer.

Drill the whole track