On August 26, 2025, the open-source ecosystem was shaken by a new supply chain attack that targeted Nx, a popular build system used by thousands of developers. Malicious package versions were published to npm, silently stealing sensitive developer assets like GitHub tokens, SSH keys, npm credentials, and even crypto wallets. The attack, dubbed s1ngularity after …