Uploaded August 2026 | Updated September 2026, 1 hour ago
Olivia BrownOlivia BrownOlivia Brown (Lubrizol, US)
On August 26, 2025, nx npm packages were compromised in a supply‑chain attack. It was one of the first documented supply‑chain attacks to weaponize Claude, Gemini, and Q Command‑Line‑Interface (CLI) developer tools. The malware stole GitHub tokens, npm credentials, SSH keys, and cryptocurrency wallets from thousands of developer systems within hours, and exfiltrated the data to over 1,000 attacker‑controlled repositories in victim accounts.
Other novel aspects of the campaign include LLM‑powered reconnaissance, triple‑base64 encoding, and a denial‑of‑service persistence mechanism. This 30‑minute presentation thoroughly explains this attack, how we found it, and what the malware script did. Attendees will learn how to detect AI‑assisted malware in their supply chains, implement defensive scanning strategies, and understand emerging attack vectors that weaponize the very AI tools designed to help developers.
---
Olivia Brown is a cyber threat intelligence analyst at Socket. Previously, she has worked for the US State Department and the US Defense Department in roles focused on cybersecurity. She has a Master's in Strategy, Cybersecurity, and Intelligence from the Johns Hopkins School of Advanced International Studies. She also attended Johns Hopkins for her undergraduate degree, where she double majored in Computer Science and International Studies.
Olivia BrownOlivia BrownOlivia Brown (Lubrizol, US)
On August 26, 2025, nx npm packages were compromised in a supply‑chain attack. It was one of the first documented supply‑chain attacks to weaponize Claude, Gemini, and Q Command‑Line‑Interface (CLI) developer tools. The malware stole GitHub tokens, npm credentials, SSH keys, and cryptocurrency wallets from thousands of developer systems within hours, and exfiltrated the data to over 1,000 attacker‑controlled repositories in victim accounts.
Other novel aspects of the campaign include LLM‑powered reconnaissance, triple‑base64 encoding, and a denial‑of‑service persistence mechanism. This 30‑minute presentation thoroughly explains this attack, how we found it, and what the malware script did. Attendees will learn how to detect AI‑assisted malware in their supply chains, implement defensive scanning strategies, and understand emerging attack vectors that weaponize the very AI tools designed to help developers.
---
Olivia Brown is a cyber threat intelligence analyst at Socket. Previously, she has worked for the US State Department and the US Defense Department in roles focused on cybersecurity. She has a Master's in Strategy, Cybersecurity, and Intelligence from the Johns Hopkins School of Advanced International Studies. She also attended Johns Hopkins for her undergraduate degree, where she double majored in Computer Science and International Studies.










