Skip to content
Xygeni Logo White
  • Products
    Agentic AI
    • DevAI AI Assistant & Automation for Devs
    • CoreAIRisk Intelligence & Orchestration
    AI-Powered AppSec
    • AI SecurityDetect AI risks hidden in prompts, skills, and MCP configs
    • SASTHigh-precision SAST with zero-noise and AI remediation
    • SCAReachability, malware detection, and safe updates.
    • DASTRuntime Application Security Testing
    • Secrets SecuritySecrets Detection & Auto-Revocation
    • CI/CD SecurityPipeline & Build Protection
    • IaC SecurityCloud & Config Security
    • API SecurityFind the Exposure Before You Deploy It
    Posture Management
    • ASPMUnified risk view, asset inventory, and compliance.
    Advanced Threats
    • Malware DefenseSupply Chain Malware Protection
    • Build SecurityBuild Integrity & Provenance
    • Anomaly DetectionBehavioral Threat Detection
    • ShieldBlock malicious packages before they execute
    Download whitepaper
  • Solutions
    Who Xygeni is built for
    • DevelopersFix issues in IDEs with minimal noise and friction.
    • DevOps & DevSecOpsAutomated policies, visibility, and remediation at scale.
    • Security Leaders (CISO)Posture management, compliance, and reporting.
  • Resources
    DISCOVER
    • Resource LibraryAll Resources in One Place
    • Product DatasheetsOfficial Product Specs
    LEARN
    • Webinars & VideosTalks, Demos & Tutorials
    • ArticlesSecurity & AppSec Insights
    • Reports & GuidesIn-depth Security Research
    • GlossaryAppSec & DevSecOps Terms
    THREAT INTELLIGENCE
    • Malicious Code Digest​ Resource LibraryThreat Intelligence Feed
    Download whitepaper
  • Company
    • AboutMission & Team
    • Case StudiesReal-world impact
    • PartnersResellers and technology partners
    • Press MediaNews & Announcements
    • EventsStay up to date with upcoming events
    • Contact UsGet in Touch
  • Pricing
  • Blog
  • Login
Start Free
Book a Demo

Category: Attacks Analysis

Malicious npm Package in Baileys Fork (Skyzopedia Case)

Malicious npm Package

Malicious npm package abuses a Baileys fork to inject runtime spam behavior through a GitHub-controlled payload.

allintext:login filetype:log – How Exposed Logs Leak Credentials

allintextlogin filetypelog

allintext:login filetype:log exposes public log files with credentials and tokens. Learn how to stop log-based data leaks.

Shai-Hulud 3.0: npm Malware Worn

Shai-Hulud 3.0 - npm Malware Worn - shai-hulud malware

Shai-Hulud 3.0 is the latest shai-hulud npm malware, a worm that spreads automatically through npm packages.

React2Shell: CVE-2025-55182 and the Next.js RCE Risk

React2Shell - CVE-2025-55182 - RCE risk

React2Shell (CVE-2025-55182) creates a critical Next.js RCE risk. Understand the impact and what to patch immediately.

Shai-Hulud 2.0 NPM Supply Chain Attack

shai hulud - npm supply chain attack

Shai Hulud turns the npm supply chain attack into a cross-ecosystem risk. Understand the impact, exposures, and how to stay protected.

Npm Packages Masquerade as Benign UI Libraries in North Korea’s “Contagious Interview” Supply-Chain Attack

Npm Packages -Contagious Interview

Newly detected malicious npm packages masquerade as harmless front-end helpers but contain malicious obfuscated code.

Zero Day Vulnerability: Detect and Block Attacks Early

Zero Day Vulnerability -Zero Day Vulnerability Exploits - Zero Day exploit

Learn what a zero day vulnerability is, how a zero day exploit works, and how to stop zero day vulnerability exploits early.

CVE-2025-30065: Apache Parquet Avro Exploit

CVE-2025-30065 - Apache Parquet - Parquet Avro

Discover CVE-2025-30065 in Apache Parquet and Parquet Avro. Learn the risks, real attack paths, and how to secure pipelines with Xygeni.

Shai-Hulud: The npm Packages Worm Explained

Shai hulud - npm packages - supply chain attack

Shai-Hulud npm worm: Read all you need to know about this massive supply chain attack with the latest updates and IoCs.

MITRE ATT&CK Framework Explained for Developers

mitre attack - mitre att&ck - MITRE attack framework - the mitre att&ck framework.

Learn how attack surface management and external attack surface management work in DevSecOps. See why the MITRE ATT&CK framework matters.

Request.get in Flask: The Simple Injection Vector You Might Miss

requests.get, flask -request, flask request form

Fake credit card generator tools like namso gen often hide malware download risks. Secure your SDLC before threats spread.

The Wrong Way to Get User Input in Python (And the Secure Alternative)

python user input - user input python - how to get user input in python

Fake credit card generator tools like namso gen often hide malware download risks. Secure your SDLC before threats spread.

← Previous
Next →
Xygeni Logo White

© 2026 Xygeni. All rights reserved

Linkedin-in X-twitter Youtube

Products

  • DevAI
  • CoreAI
  • SAST
  • SCA
  • DAST
  • Secrets Security
  • CI/CD Security
  • IaC Security
  • ASPM
  • Malware Defense
  • Build Security
  • Anomaly Detection

Resources

  • Pricing
  • Resource Library
  • Datasheets & Product Briefs
  • eBooks
  • Whitepapers & Reports
  • Articles
  • Product Tour
  • Video Demonstrations
  • Webinars
  • Glossary
  • Top Cybersecurity Tools Lists
  • Malicious Code Digest​

Company

  • About
  • Join Newsletter
  • Case Studies
  • Events
  • Press Media
  • Contact Us

Legal

  • Privacy Policy
  • Cookie Policy
  • Legal Notice
  • Platform Terms
  • Website Terms
  • Subprocessors
  • DPA