PhantomBot: A Typosquat Campaign That Pivoted From Credential Theft to a Turnkey Botnet Kit

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
AWS Lambda npm Dependency Confusion Attack: The 24712-pl Campaign

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
alone5511 npm Dependency Confusion Attack

An npm dependency confusion attack used eight malicious packages to fingerprint hosts and send RCE telemetry to Telegram.
AI Security Risks in DevSecOps: Code, Pipelines, and Agents

Explore AI security risks in DevSecOps and understand how they affect the software development lifecycle and automation processes.
EVM/DeFi npm Typosquatting Attack Steals Developer Keys

A npm typosquatting attack used six malicious EVM/DeFi packages to steal developer keys, wallets, secrets, and .env files.
FauxCode: Reverse-Engineered Claude Code Routes Through Attackers

FauxCode Claude Code npm malware used fake CLI packages to intercept API traffic through CA-bundle MITM and base URL hijacking.
DevTap npm Typosquatting Attack: Six Malicious Packages Target Developer Workstations

DevTap npm typosquatting attack used six malicious packages to spy on developer workstations and abuse npm trust.
Inject Environment Variables to the Build Process Securely

Inject environment variables to the build process securely. Learn how to prevent leaks and protect secrets in CI/CD pipelines.
Axios npm Compromise: What Happened, Who Is Affected, and How to Prevent It

Xygeni identifies Nyx: a sophisticated npm Infostealer hijacking Discord and crypto wallets using advanced runtime decryption.
LiteLLM Attack: How Xygeni Stops Secret Exposure Fast

LiteLLM attack exposed critical secrets. See how Xygeni detects, verifies, and revokes credentials before attackers use them.
LiteLLM Supply Chain Attack: How TeamPCP Backdoored AI Infrastructure

Explore the security breach of LiteLLM, affecting millions of users with multi-stage payloads and devastating consequences.
AI Coding Assistant Security: How to Prevent Vulnerabilities in AI-Generated Code

AI coding assistant security guide: prevent vulnerabilities in AI-generated code, detect risks early, and secure your pipelines in real time.