Nx Package Compromise is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 15, 2025; most recent activity December 15, 2025.
Nx Package Compromise is a threat campaign described within the context of npm supply chain attacks. The campaign involves injecting malicious payloads into npm packages to compromise downstream projects via dependencies, highlighting the persistent risk of software supply chains in the Node.js ecosystem and the need for strong provenance, monitoring, and rapid response.
AWS incident response teams have been actively addressing high-profile software supply chain threats targeting third-party software repositories. These campaigns have affected organizations across various sectors,…