Skip to content
Xygeni Logo White
  • Products
    Agentic AI
    • DevAI AI Assistant & Automation for Devs
    • CoreAIRisk Intelligence & Orchestration
    AI-Powered AppSec
    • AI SecurityDetect AI risks hidden in prompts, skills, and MCP configs
    • SASTHigh-precision SAST with zero-noise and AI remediation
    • SCAReachability, malware detection, and safe updates.
    • DASTRuntime Application Security Testing
    • Secrets SecuritySecrets Detection & Auto-Revocation
    • CI/CD SecurityPipeline & Build Protection
    • IaC SecurityCloud & Config Security
    • API SecurityFind the Exposure Before You Deploy It
    Posture Management
    • ASPMUnified risk view, asset inventory, and compliance.
    Advanced Threats
    • Malware DefenseSupply Chain Malware Protection
    • Build SecurityBuild Integrity & Provenance
    • Anomaly DetectionBehavioral Threat Detection
    • ShieldBlock malicious packages before they execute
    Download whitepaper
  • Solutions
    Who Xygeni is built for
    • DevelopersFix issues in IDEs with minimal noise and friction.
    • DevOps & DevSecOpsAutomated policies, visibility, and remediation at scale.
    • Security Leaders (CISO)Posture management, compliance, and reporting.
  • Resources
    DISCOVER
    • Resource LibraryAll Resources in One Place
    • Product DatasheetsOfficial Product Specs
    LEARN
    • Webinars & VideosTalks, Demos & Tutorials
    • ArticlesSecurity & AppSec Insights
    • Reports & GuidesIn-depth Security Research
    • GlossaryAppSec & DevSecOps Terms
    THREAT INTELLIGENCE
    • Malicious Code Digest​ Resource LibraryThreat Intelligence Feed
    Download whitepaper
  • Company
    • AboutMission & Team
    • Case StudiesReal-world impact
    • PartnersResellers and technology partners
    • Press MediaNews & Announcements
    • EventsStay up to date with upcoming events
    • Contact UsGet in Touch
  • Pricing
  • Blog
  • Login
Start Free
Book a Demo

Category: Attacks Analysis

Risky Business: The Anti-Proctoring Packages That Delete Themselves

Risky Business: Self-Deleting npm Packages Explained

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

Cyber Threats Explained: The Main Types Security Teams Should Know

types of cyber threats

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

The npm Worm Playbook: Same Attack, Three Times in Eight Months

npm worm playbook

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

JavacDoor: A Maven Artifact That Ran During Compilation, Not Installation

JavacDoor, Maven Malware That Runs at Compile Time

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

Npm Supply Chain Attacks: Biggest Incidents & How to Stop Them

Npm Supply Chain Attacks

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

How AI Agents Can Automate a Ransomware Attack: What JadePuffer Just Proved

How AI Agents Can Automate a Ransomware Attack

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

QuietPolyfill: An NPM dropper that resurrected

QuietPolyfill, an NPM dropper that resurrected

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

Rogue by Design: How a Sandboxed Pre-Release Model Jailbroke Itself and Hacked Hugging Face to Cheat an Exam

rogue by design

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

PointBlank: a fully-featured Python RAT that ran its command channel through a free note-hosting service

PointBlank: PyPI RAT Hides C2 in a JSON-Bin Service

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

Slopsquatting evolution: From AI Curiosity to Agent RCE

Slopsquatting Evolution

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

PhantomSync: eight crypto-developer npm packages hide a delayed, self-persisting dropper

PhantomSync: npm Crypto Packages Hide Wallet Stealer

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

FauxUV: fake PyPI uv helpers that open an unauthenticated Jupyter server to the internet

FauxUV: Fake PyPI uv Packages Open Jupyter to the Web

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

Next →
Xygeni Logo White

© 2026 Xygeni. All rights reserved

Linkedin-in X-twitter Youtube

Products

  • DevAI
  • CoreAI
  • SAST
  • SCA
  • DAST
  • Secrets Security
  • CI/CD Security
  • IaC Security
  • ASPM
  • Malware Defense
  • Build Security
  • Anomaly Detection

Resources

  • Pricing
  • Resource Library
  • Datasheets & Product Briefs
  • eBooks
  • Whitepapers & Reports
  • Articles
  • Product Tour
  • Video Demonstrations
  • Webinars
  • Glossary
  • Top Cybersecurity Tools Lists
  • Malicious Code Digest​

Company

  • About
  • Join Newsletter
  • Case Studies
  • Events
  • Press Media
  • Contact Us

Legal

  • Privacy Policy
  • Cookie Policy
  • Legal Notice
  • Platform Terms
  • Website Terms
  • Subprocessors
  • DPA