Blogs

Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident

Snyk

On August 26–27, 2025 (UTC), eight malicious Nx and Nx Powerpack releases were pushed to npm across two version lines and were live for ~5 hours 20 minutes before removal.

Visit Site

Blogs Snyk

Why AI Coding Agents Keep Writing Broken Access ControlSnyk What is a Container Registry security?Snyk Using Snyk reporting for data-driven securitySnyk Snyk in 30: Open source security for Atlassian Bitbucket CloudSnyk 10 best practices to containerize Node.js web applications with DockerSnyk How to verify and secure your Mastodon accountSnyk Cloud Security Trends & Challenges: Complete GuideCybersecurity Exchange Security Implementation for Responsible AI: A Practical FrameworkCybersecurity Exchange 10 best AI observability tools for monitoring and evaluating agents in 2026Mintlify How to Conduct an AI Agent Security Audit [+ Checklist]Zapier DevSecOps: Why Security Shouldn’t be Sacrificed for SpeedThenewstack Security Considerations for API-Driven Apps Deployed to CloudThenewstack Oso Unbundles Security AuthorizationThenewstack Pulumi ESC and External Secrets Operator: The Perfect Solution for TodayPulumi Pulumi Neo Now Supports AGENTS.mdPulumi IaC Best Practices: Implementing RBAC and SecurityPulumi Go Concurrency Patterns: Context - The Go Programming LanguageGo How to serve trillions of tokens for trillion-parameter coding agentsModal Do AI Agents Need a Semantic Layer?Motherduck Building a Remote MCP Server: OAuth, Tool Design & Lessons from 4,000+ AI Queries | MotherDuckMotherduck