Category: Attacks Analysis

RuntimeBroker npm Typosquat Plants Crypto Clipper

RuntimeBroker: an npm Typosquat Plants a 40-Chain Crypto-Clipper as a Cross-OS \”System Runtime Helper”\

RuntimeBroker npm typosquat deploys a cross-OS crypto clipper targeting 40+ blockchains through fake runtime helper services.
AuditorTrap

AuditorTrap: A 22-Package Fake Crypto Security Guild on npm With Two Parallel Payloads

Read about AuditorTrap: Fake Web3 security tools on npm steal wallets, secrets, and API keys through malicious MCP packages & CI/CD payloads.
PhantomBot From Credential Theft to Botnet

PhantomBot: A Typosquat Campaign That Pivoted From Credential Theft to a Turnkey Botnet Kit

PhantomBot evolved from credential theft to a turnkey botnet in 48 hours. Discover the npm campaign behind it, read now!
AWS Lambda npm Dependency Confusion Attack The 24712-pl Campaign

AWS Lambda npm Dependency Confusion Attack: The 24712-pl Campaign

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
alone5511 npm Dependency Confusion Attack

alone5511 npm Dependency Confusion Attack

An npm dependency confusion attack used eight malicious packages to fingerprint hosts and send RCE telemetry to Telegram.
EVMDeFi npm Typosquatting Attack Steals Developer Keys

EVM/DeFi npm Typosquatting Attack Steals Developer Keys

A npm typosquatting attack used six malicious EVM/DeFi packages to steal developer keys, wallets, secrets, and .env files.
FauxCode When Your Reverse-Engineered Claude Code Quietly Routes Through the Attacker

FauxCode: Reverse-Engineered Claude Code Routes Through Attackers

FauxCode Claude Code npm malware used fake CLI packages to intercept API traffic through CA-bundle MITM and base URL hijacking.
DevTap npm Typosquatting Attack

DevTap npm Typosquatting Attack: Six Malicious Packages Target Developer Workstations

DevTap npm typosquatting attack used six malicious packages to spy on developer workstations and abuse npm trust.
Axios npm Compromise

Axios npm Compromise: What Happened, Who Is Affected, and How to Prevent It

Axios npm compromise explained. Discover how attackers access secrets and how to prevent runtime data leaks.
8 min read
LiteLLM Supply Chain Attack

LiteLLM Attack: How Xygeni Stops Secret Exposure Fast

LiteLLM attack exposed critical secrets. See how Xygeni detects, verifies, and revokes credentials before attackers use them.
7 min read
LiteLLM Supply Chain Attack

LiteLLM Supply Chain Attack: How TeamPCP Backdoored AI Infrastructure

Explore the security breach of LiteLLM, affecting millions of users with multi-stage payloads and devastating consequences.
npm Infostealer

New npm Infostealer Discovery: Nyx Stealer Hijacks Discord Sessions

Xygeni identifies Nyx: a sophisticated npm Infostealer hijacking Discord and crypto wallets using advanced runtime decryption.
7 min read