Category: Attacks Analysis

Malicious npm Package

Malicious npm Package in Baileys Fork (Skyzopedia Case)

Malicious npm package abuses a Baileys fork to inject runtime spam behavior through a GitHub-controlled payload.
5 min read
allintextlogin filetypelog

allintext:login filetype:log – How Exposed Logs Leak Credentials

allintext:login filetype:log exposes public log files with credentials and tokens. Learn how to stop log-based data leaks.
6 min read
Shai-Hulud 3.0 - npm Malware Worn - shai-hulud malware

Shai-Hulud 3.0: npm Malware Worm

Shai-Hulud 3.0 is the latest shai-hulud npm malware, a worm that spreads automatically through npm packages.
5 min read
React2Shell - CVE-2025-55182 - RCE risk

React2Shell: CVE-2025-55182 and the Next.js RCE Risk

React2Shell (CVE-2025-55182) creates a critical Next.js RCE risk. Understand the impact and what to patch immediately.
7 min read
shai hulud - npm supply chain attack

Shai-Hulud 2.0 NPM Supply Chain Attack

Shai Hulud turns the npm supply chain attack into a cross-ecosystem risk. Understand the impact, exposures, and how to stay protected.
15 min read
Npm Packages -Contagious Interview

Npm Packages Masquerade as Benign UI Libraries in North Korea’s “Contagious Interview” Supply-Chain Attack

Newly detected malicious npm packages masquerade as harmless front-end helpers but contain malicious obfuscated code.
5 min read
Zero Day Vulnerability -Zero Day Vulnerability Exploits - Zero Day exploit

Zero Day Vulnerability: Detect and Block Attacks Early

Learn what a zero day vulnerability is, how a zero day exploit works, and how to stop zero day vulnerability exploits early.
7 min read
CVE-2025-30065 - Apache Parquet - Parquet Avro

CVE-2025-30065: Apache Parquet Avro Exploit

Discover CVE-2025-30065 in Apache Parquet and Parquet Avro. Learn the risks, real attack paths, and how to secure pipelines with Xygeni.
7 min read
Shai hulud - npm packages - supply chain attack

Shai-Hulud: The npm Packages Worm Explained

Shai-Hulud npm worm: Read all you need to know about this massive supply chain attack with the latest updates and IoCs.
12 min read
mitre attack - mitre att&ck - MITRE attack framework - the mitre att&ck framework.

MITRE ATT&CK Framework Explained for Developers

Learn how attack surface management and external attack surface management work in DevSecOps. See why the MITRE ATT&CK framework matters.
8 min read
requests.get, flask -request, flask request form

Request.get in Flask: The Simple Injection Vector You Might Miss

Prevent injection flaws from unsafe requests.get and flask request form. Learn how to validate inputs and secure Flask apps in CI/CD!
python user input - user input python - how to get user input in python

The Wrong Way to Get User Input in Python (And the Secure Alternative)

Learn the risks of insecure Python user input & discover how to get user input in Python safely with validation, sanitization, CI/CD checks!