{"_id":"@bluefire-redteam/nx-s1ngularity-check","_rev":"6-686d33c9f911e54c6c272f9a0cf8abbc","name":"@bluefire-redteam/nx-s1ngularity-check","dist-tags":{"latest":"1.0.8"},"versions":{"1.0.3":{"name":"@bluefire-redteam/nx-s1ngularity-check","version":"1.0.3","keywords":["security","supply-chain","scanner","npm","nx","bluefire"],"author":{"name":"Bluefire Redteam","email":"contact@bluefireredteam.com"},"license":"MIT","_id":"@bluefire-redteam/nx-s1ngularity-check@1.0.3","maintainers":[{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"}],"homepage":"https://bluefireredteam.com","bugs":{"url":"https://github.com/bluefire-redteam/bluefire-nx-check/issues"},"bin":{"bluefire-nx-check":"bin/index.js"},"dist":{"shasum":"995604f20648a4620b6dee7f8a801bbe0fe9c864","tarball":"https://registry.npmjs.org/@bluefire-redteam/nx-s1ngularity-check/-/nx-s1ngularity-check-1.0.3.tgz","fileCount":5,"integrity":"sha512-B2oB7OIopwVfM3vJK+HGrAJptNhdWG4Nz5eR/FxK2aL6OlIkTORxspERSTdCNq+aj0d72XU6pEmCxin+lusFfw==","signatures":[{"sig":"MEUCIGiMamFf1m+yLT/ugO+W7btFzP2w0Z4NRovmjFpBGUvjAiEAlzOO4mgJF11vhSDbR0GLlh4wcoVrX+bor+Ilh6EzRlQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11934},"type":"module","engines":{"node":">=18"},"gitHead":"78660a8d41e67c8eb5ae480a8e463edefd1c3776","_npmUser":{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"},"repository":{"url":"git+https://github.com/bluefire-redteam/bluefire-nx-check.git","type":"git"},"_npmVersion":"11.4.2","description":"Bluefire Redteam scanner for Nx 's1ngularity' supply-chain compromise (malicious versions, IoCs, exfil).","directories":{},"_nodeVersion":"24.4.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/nx-s1ngularity-check_1.0.3_1756315471193_0.481838373190574","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@bluefire-redteam/nx-s1ngularity-check","version":"1.0.4","keywords":["security","supply-chain","scanner","npm","nx","bluefire"],"author":{"name":"Bluefire Redteam","email":"contact@bluefireredteam.com"},"license":"MIT","_id":"@bluefire-redteam/nx-s1ngularity-check@1.0.4","maintainers":[{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"}],"homepage":"https://github.com/bluefire-redteam/bluefire-nx-check#readme","bugs":{"url":"https://github.com/bluefire-redteam/bluefire-nx-check/issues"},"bin":{"bluefire-nx-check":"bin/index.js"},"dist":{"shasum":"0e2ee20dc240e30b33d2aded80c44d22d1de2b17","tarball":"https://registry.npmjs.org/@bluefire-redteam/nx-s1ngularity-check/-/nx-s1ngularity-check-1.0.4.tgz","fileCount":5,"integrity":"sha512-4c73kvzMjR5QTDe7qKkXBFtS/UI+HgG71ezG8+En1x2/+J/M+GOsD0+TYga1FWA+pfZ12HhIhrY+dnaadqx9bg==","signatures":[{"sig":"MEUCIDWGnV3z7QW6X2D5KzF36S1WAaJLiSY5WezB4GE6xUTaAiEAwmqe/DUKFKknMC5wMp5bvx6u73jdP5uzydeO96xj9G4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11855},"type":"module","engines":{"node":">=18"},"gitHead":"993e0c1c0a6b48bd710ba167eb7d773366a73a56","_npmUser":{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"},"repository":{"url":"git+https://github.com/bluefire-redteam/bluefire-nx-check.git","type":"git"},"_npmVersion":"11.4.2","description":"Bluefire Redteam scanner for Nx 's1ngularity' supply-chain compromise (malicious versions, IoCs, exfil).","directories":{},"_nodeVersion":"24.4.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/nx-s1ngularity-check_1.0.4_1756317550812_0.5760274475416671","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"name":"@bluefire-redteam/nx-s1ngularity-check","version":"1.0.5","keywords":["security","supply-chain","scanner","npm","nx","bluefire"],"author":{"name":"Bluefire Redteam","email":"contact@bluefireredteam.com"},"license":"MIT","_id":"@bluefire-redteam/nx-s1ngularity-check@1.0.5","maintainers":[{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"}],"homepage":"https://github.com/bluefire-redteam/bluefire-nx-check#readme","bugs":{"url":"https://github.com/bluefire-redteam/bluefire-nx-check/issues"},"bin":{"bluefire-nx-check":"bin/index.js"},"dist":{"shasum":"3391e045b179ae90dfd145e5c774c506fba1c268","tarball":"https://registry.npmjs.org/@bluefire-redteam/nx-s1ngularity-check/-/nx-s1ngularity-check-1.0.5.tgz","fileCount":5,"integrity":"sha512-dmYv/Ef8+J2rVnDiE0hwvocgBI+Q7uxmmnjT/CYgmqzRGVbDFC45zyVNPs8EWE2BYmalox5SEIU2wCl4xCoDxA==","signatures":[{"sig":"MEQCID5s3zXWqrCZbflu2ogperyBwpUY+B0a1d7oSubEHeSvAiA3AvHPZqciOdYR6y4bbu5dhX3EuwNlytKMvAfzPRajOg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11660},"type":"module","engines":{"node":">=18"},"gitHead":"d7a71af3ce0aed614445149ad86c000bb1cb1180","_npmUser":{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"},"repository":{"url":"git+https://github.com/bluefire-redteam/bluefire-nx-check.git","type":"git"},"_npmVersion":"11.4.2","description":"Bluefire Redteam scanner for Nx 's1ngularity' supply-chain compromise (malicious versions, IoCs, exfil).","directories":{},"_nodeVersion":"24.4.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/nx-s1ngularity-check_1.0.5_1756318740830_0.3733137828999131","host":"s3://npm-registry-packages-npm-production"}},"1.0.6":{"name":"@bluefire-redteam/nx-s1ngularity-check","version":"1.0.6","keywords":["security","supply-chain","scanner","npm","nx","bluefire"],"author":{"name":"Bluefire Redteam","email":"contact@bluefireredteam.com"},"license":"MIT","_id":"@bluefire-redteam/nx-s1ngularity-check@1.0.6","maintainers":[{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"}],"homepage":"https://github.com/bluefire-redteam/bluefire-nx-check#readme","bugs":{"url":"https://github.com/bluefire-redteam/bluefire-nx-check/issues"},"bin":{"bluefire-nx-check":"bin/index.js"},"dist":{"shasum":"7ae3b7ca2b093822854ea84f0a662deef361a647","tarball":"https://registry.npmjs.org/@bluefire-redteam/nx-s1ngularity-check/-/nx-s1ngularity-check-1.0.6.tgz","fileCount":5,"integrity":"sha512-N5maUFZ0WET1LbuaMnRoX+3QBDZmbUsKbUHkQCXsEPTgxrsKH0x3+dYaY0ptdFlE7Wa8fI9ld646Ih9ptUz9Mw==","signatures":[{"sig":"MEYCIQCaEZeGq0lJ+uL/ZT2IacHge/YBOAjEq3cMhWKiToF5dwIhAKoTcE7cXa1glRwjo4s1UZAYW0W2tshGx+/LxpgYncsm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11596},"type":"module","engines":{"node":">=18"},"gitHead":"e55d7b4ede7ec0c4ddfe43d46c98027c788952b3","_npmUser":{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"},"repository":{"url":"git+https://github.com/bluefire-redteam/bluefire-nx-check.git","type":"git"},"_npmVersion":"11.4.2","description":"Bluefire Redteam scanner for Nx 's1ngularity' supply-chain compromise (malicious versions, IoCs, exfil).","directories":{},"_nodeVersion":"24.4.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/nx-s1ngularity-check_1.0.6_1756318851708_0.00023531650790742376","host":"s3://npm-registry-packages-npm-production"}},"1.0.7":{"name":"@bluefire-redteam/nx-s1ngularity-check","version":"1.0.7","keywords":["security","supply-chain","scanner","npm","nx","bluefire"],"author":{"name":"Bluefire Redteam","email":"contact@bluefireredteam.com"},"license":"MIT","_id":"@bluefire-redteam/nx-s1ngularity-check@1.0.7","maintainers":[{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"}],"homepage":"https://github.com/bluefire-redteam/bluefire-nx-check#readme","bugs":{"url":"https://github.com/bluefire-redteam/bluefire-nx-check/issues"},"bin":{"bluefire-nx-check":"bin/index.js"},"dist":{"shasum":"be30cca08d0ce3b809ca8595953b99f232116547","tarball":"https://registry.npmjs.org/@bluefire-redteam/nx-s1ngularity-check/-/nx-s1ngularity-check-1.0.7.tgz","fileCount":5,"integrity":"sha512-XzYw0uC7dUOCQITAsFgzS6hXtj3Pzt21/SSrVdzMiqXdT4VrPkdnw8zFF+BCzo+uStd9PEN/D0fKXAlm8dYiMA==","signatures":[{"sig":"MEUCIQDvNDnoAPS87Qr/GXYW1c+dNkGq88MFox9s90eFi9t8GwIgB0uRe+vj00XmKDguyyj3Hl3mlVDElxfinf5xXpSG1mk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15646},"type":"module","engines":{"node":">=18"},"gitHead":"6a5acf690bab932d3ee975ee9800c15e5e182000","_npmUser":{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"},"repository":{"url":"git+https://github.com/bluefire-redteam/bluefire-nx-check.git","type":"git"},"_npmVersion":"11.4.2","description":"Bluefire Redteam scanner for Nx 's1ngularity' supply-chain compromise (malicious versions, IoCs, exfil).","directories":{},"_nodeVersion":"24.4.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/nx-s1ngularity-check_1.0.7_1757131664163_0.7185171119148595","host":"s3://npm-registry-packages-npm-production"}},"1.0.8":{"name":"@bluefire-redteam/nx-s1ngularity-check","version":"1.0.8","description":"Bluefire Redteam scanner for Nx 's1ngularity' supply-chain compromise (malicious versions, IoCs, exfil).","bin":{"bluefire-nx-check":"bin/index.js"},"type":"module","license":"MIT","keywords":["security","supply-chain","scanner","npm","nx","bluefire"],"repository":{"type":"git","url":"git+https://github.com/bluefire-redteam/bluefire-nx-check.git"},"bugs":{"url":"https://github.com/bluefire-redteam/bluefire-nx-check/issues"},"homepage":"https://github.com/bluefire-redteam/bluefire-nx-check#readme","author":{"name":"Bluefire Redteam","email":"contact@bluefireredteam.com"},"engines":{"node":">=18"},"publishConfig":{"access":"public"},"_id":"@bluefire-redteam/nx-s1ngularity-check@1.0.8","gitHead":"67a8ed097f92b8b0941d5dd147b658a4b6540215","_nodeVersion":"24.4.1","_npmVersion":"11.4.2","dist":{"integrity":"sha512-nhzwHudfBTtlcs8pl065NIgqZY/tjg9ILyTPFtSeliJqv3Xjas4RLkP6ASeHYCUNCJGauKM75Yd43KLaM8nJ8w==","shasum":"abc73f168cc6dad32c656f2bbaaf2e15f32f7da6","tarball":"https://registry.npmjs.org/@bluefire-redteam/nx-s1ngularity-check/-/nx-s1ngularity-check-1.0.8.tgz","fileCount":5,"unpackedSize":16930,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAoeGeSQhmMM+tXzc+ea/iuZCms9mh6oM9hXN5WVfMOdAiEAoc4X1JGG2LM6y/7P8HKR4dXAXFMPNXE4ZyVYZgKSWos="}]},"_npmUser":{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"},"directories":{},"maintainers":[{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/nx-s1ngularity-check_1.0.8_1757132053805_0.8917254784278374"},"_hasShrinkwrap":false}},"time":{"created":"2025-08-27T17:24:31.142Z","modified":"2025-09-06T04:14:14.183Z","1.0.3":"2025-08-27T17:24:31.387Z","1.0.4":"2025-08-27T17:59:10.990Z","1.0.5":"2025-08-27T18:19:01.009Z","1.0.6":"2025-08-27T18:20:51.892Z","1.0.7":"2025-09-06T04:07:44.349Z","1.0.8":"2025-09-06T04:14:13.997Z"},"bugs":{"url":"https://github.com/bluefire-redteam/bluefire-nx-check/issues"},"author":{"name":"Bluefire Redteam","email":"contact@bluefireredteam.com"},"license":"MIT","homepage":"https://github.com/bluefire-redteam/bluefire-nx-check#readme","keywords":["security","supply-chain","scanner","npm","nx","bluefire"],"repository":{"type":"git","url":"git+https://github.com/bluefire-redteam/bluefire-nx-check.git"},"description":"Bluefire Redteam scanner for Nx 's1ngularity' supply-chain compromise (malicious versions, IoCs, exfil).","maintainers":[{"name":"bluefire-redteam","email":"bluefire.redteam@gmail.com"}],"readme":"# 🔍 Bluefire Redteam's Nx \"s1ngularity\" Supply Chain Scanner(New Update)\n\n![npm (scoped)](https://img.shields.io/npm/v/%40bluefire-redteam%2Fnx-s1ngularity-check)\n\n**Free, open-source scanner from [Bluefire Redteam](https://bluefire-redteam.com)**  \nDetect if your systems or projects were impacted by the August 2025 Nx *s1ngularity* supply-chain compromise.  \n\n---\n\n## 🚨 What Happened?\nOn **Aug 26–27, 2025**, multiple malicious versions of the **Nx build system packages** were published to npm.  \nThey contained a **postinstall malware (`telemetry.js`)** that:\n- Stole **GitHub tokens, npm tokens, SSH keys, `.env` secrets, crypto wallets**\n- Abused local **AI CLI tools (Claude, Gemini, Q)** to aid reconnaissance\n- Exfiltrated stolen data into **public GitHub repos** named:\n  - `s1ngularity-repository`\n  - `s1ngularity-repository-0`\n  - `s1ngularity-repository-1`\n  - `s1ngularity-repository-<5letters>` (Phase 2)\n  - `*_bak` with description `\"S1ngularity\"` (Phase 3)\n- Modified `~/.bashrc` & `~/.zshrc` to cause forced shutdowns  \n\n👉 Thousands of secrets and repos were exposed across multiple phases of this attack.\n\n---\n\n## ✅ What This Tool Does\n`@bluefire-redteam/nx-s1ngularity-check` scans your environment for **all known indicators of compromise (IoCs):**\n\n- **Malicious versions** of Nx / @nx packages in:\n  - `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml`\n  - `npm ls` output\n- **Host IoCs:**\n  - `sudo shutdown -h 0` in `~/.bashrc` / `~/.zshrc`\n  - `/tmp/inventory.txt` or `/tmp/inventory.txt.bak`\n- **Node_modules payload check:**\n  - Detects `telemetry.js` with malicious markers across all known prompt variants (Phase 1–3)\n- **Exfil files:**\n  - Finds `results.b64` (locally or `/tmp`)  \n  - Auto-decodes up to 3x Base64 → previews decoded JSON\n- **GitHub repos (expanded detection):**\n  - Flags attacker-created repos in your account/org:\n    - `s1ngularity-repository`, `-0`, `-1`  \n    - `s1ngularity-repository-<5letters>`  \n    - Any repo suffixed with `_bak` or with description `\"S1ngularity\"`  \n  - Requires `GH_TOKEN` or `GITHUB_TOKEN` for API access\n- **GitHub search mode (NEW in v1.0.7):**\n  - Use `--search <query>` to check all public repos on GitHub for IoCs\n\n---\n\n## 🚀 Quick Start\n\nRun directly with `npx` (no install needed):\n\n```bash\nnpx @bluefire-redteam/nx-s1ngularity-check\n```\n\n> ⚠️ Use the scoped name `@bluefire-redteam/nx-s1ngularity-check`.  \n> Do **not** use any unscoped package — that is not us!\n\n---\n\n## 🔍 Usage Examples\n\n### Scan current project\n```bash\nnpx @bluefire-redteam/nx-s1ngularity-check\n```\n\n### Scan a GitHub user’s repos\n```bash\nGH_TOKEN=ghp_xxx npx @bluefire-redteam/nx-s1ngularity-check --user someuser\n```\n\n### Scan a GitHub organization\n```bash\nGH_TOKEN=ghp_xxx npx @bluefire-redteam/nx-s1ngularity-check --org myorg\n```\n\n### Search all public GitHub repos (NEW in v1.0.7)\n```bash\nGH_TOKEN=ghp_xxx npx @bluefire-redteam/nx-s1ngularity-check --search s1ngularity-repository\n```\n\n---\n\n## 🖥️ Example Output\n\n```bash\n=== Bluefire Nx s1ngularity Comprehensive Scanner ===\n\n❌ Suspicious GitHub repos detected\n\n--- JSON ---\n{\n  \"summary\": {\n    \"affectedFound\": false,\n    \"iocFound\": false,\n    \"nodeModulesFound\": false,\n    \"resultsB64Found\": false,\n    \"ghFound\": true,\n    \"severity\": \"high\"\n  }\n}\n```\n\n---\n\n## 🛡️ What To Do If Compromised\n1. **Remove malicious Nx versions:**\n   ```bash\n   rm -rf node_modules\n   npm cache clean --force\n   npm install nx@latest\n   ```\n2. **Clean persistence:**\n   - Remove `sudo shutdown -h 0` lines from `~/.bashrc` / `~/.zshrc`\n   - Delete `/tmp/inventory.txt*`\n3. **Check GitHub repos:**  \n   - Delete suspicious repos flagged by the scanner\n4. **Rotate ALL credentials:**  \n   - GitHub tokens, npm tokens, SSH keys, API keys, environment secrets\n   - Move cryptocurrency funds to new wallets immediately\n5. **Audit CI/CD pipelines & logs** for suspicious activity\n\n---\n\n## 🏢 About Bluefire Redteam\nBluefire Redteam is a global leader in **offensive security, AI red teaming, and supply chain defense**.  \nWe built this tool to help the community **detect, contain, and respond** to the Nx compromise.\n\n👉 Need help with **incident response or supply chain hardening?**  \nContact us: [bluefire-redteam.com](https://bluefire-redteam.com)\n\n---\n\n## 📦 Version Updates\n- **v1.0.7 (latest)** — Added Phase 2/3 repo detection, expanded `telemetry.js` IoCs, new `--search` flag  \n- **v1.0.6** — Added `--org` and `--user` scanning, initial GitHub integration  \n- **v1.0.5 and earlier** — Initial release with local project + host scanning\n\n---\n\n## 📜 License\nMIT – free to use and share. Please credit **Bluefire Redteam** when referencing.\n\n","readmeFilename":"README.md"}