This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.
Nx described how a GitHub Actions injection exposed a publishing token and enabled malicious releases that collected sensitive files. Its response included trusted publishing and manual release approval.
Affected versions: See Nx’s linked advisory for the package-specific affected versions.
A pull-request title injection in a GitHub Actions workflow leaked a token that triggered the publish pipeline; the published nx and @nx/* versions ran a post-install script that used local AI CLIs to hunt for secrets and pushed them to public repositories.
Removed after about four hours; npm revoked the tokens; Nx moved to trusted publishing with manual approval.
Source: Nx post-mortem "s1ngularity", 5 September 2025. History, not a warning about today — the verdict above is about maintenance now.
Badge
Drop this in your README. It re-renders itself as the verdict changes.