Category: Must Read

Risky Business: Self-Deleting npm Packages Explained

Risky Business: The Anti-Proctoring Packages That Delete Themselves

Risky Business: packages that delete themselves within minutes. Xygeni tracked 16 npm packages, 3 payloads, one shared technique. Dive in!
JavacDoor, Maven Malware That Runs at Compile Time

JavacDoor: A Maven Artifact That Ran During Compilation, Not Installation

A Maven jar with zero install hooks and zero imports still ran a live C2 payload, just by sitting on the compiler's path. Dive in!
QuietPolyfill, an NPM dropper that resurrected

QuietPolyfill: An NPM dropper that resurrected

QuietPolyfill: an npm dropper that triggers on import, bypassing --ignore-scripts entirely, and came back a day later. Take a look!
rogue by design

Rogue by Design: How a Sandboxed Pre-Release Model Jailbroke Itself and Hacked Hugging Face to Cheat an Exam

An OpenAI model escaped its sandbox and breached Hugging Face on its own, to cheat a benchmark exam. No human attacker. Here's how.
PointBlank: PyPI RAT Hides C2 in a JSON-Bin Service

PointBlank: a fully-featured Python RAT that ran its command channel through a free note-hosting service

A PyPI package called gcli-control shipped a full Windows RAT openly & ran its command channel through npoint.io instead of a server it owned
PhantomSync: npm Crypto Packages Hide Wallet Stealer

PhantomSync: eight crypto-developer npm packages hide a delayed, self-persisting dropper

PhantomSync: 8 npm crypto packages hide a delayed dropper that steals wallet keys and exfiltrates via IPFS. IOCs and detection guide.
FauxUV: Fake PyPI uv Packages Open Jupyter to the Web

FauxUV: fake PyPI uv helpers that open an unauthenticated Jupyter server to the internet

FauxUV: fake PyPI uv helper packages install a passwordless JupyterLab server, then expose it to the internet via reverse tunnel.
forge-jsxy npm Infostealer: IOCs & Detection Guide

forge-jsxy: The npm Infostealer That Keeps Changing Its Name

Renamed npm infostealer forge-jsxy → pinokio-redis steals crypto wallets & credentials. IOCs, timeline, and defender guidance inside.
GhostTracker: npm Trojan Rebranded in 74 Minutes — Same C2

GhostTracker: an npm trojan that rebranded within hours of takedown — and kept the same C2

GhostTracker rebranded 74 minutes after takedown, same C2, new names. Do you know how the npm trojan works and what to block first?
SkillLeak, Browser Credential Theft via MCP Skill

SkillLeak: A Browser-Credential Decryptor Delivered Through an MCP Skill

SkillLeak hides a Chrome/Edge password decryptor inside an MCP skill, not an install hook. Learn how it works and what defenders should check.
Zero Trust SDLC

Keys to use AI cybersecurity, Zero Trust SDLC, how to secure AI-generated code, AI Security

Zero Trust SDLC means securing what AI produces and uses. Learn the five surfaces, real attacks, and how to close the AI security gap now.
10 min read
ai inventory software

What Is an AI Inventory? A Practical Guide to AI Asset Discovery, AI-BOM and Shadow AI

What is an AI inventory? A practical guide to AI asset discovery, AI-BOM generation, shadow AI, and EU AI Act compliance.