s1ngularity Stealer

First seen
2023-01-15 00:00:00
Malware type
credential-stealer
Profile updated
2026-07-07 14:34:22

Targeted industries: technology-and-telecommunications financial-services

Context

According to StepSecurity, this is a stealer deployed through a compromised Nx package, targeting system environment properties, cryptocurrency wallets, and development credentials. Data is exfiltrated to Github using stolen tokens.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.S1Ngularity (report)
  • stepsecurity.io — Supply Chain Security Alert Popular Nx Build System Package Compromised With Data Stealing Malware (report)

External references