Skip to content
Xygeni Logo White
  • Products
    Agentic AI
    • DevAI AI Assistant & Automation for Devs
    • CoreAIRisk Intelligence & Orchestration
    AI-Powered AppSec
    • AI SecurityDetect AI risks hidden in prompts, skills, and MCP configs
    • SASTHigh-precision SAST with zero-noise and AI remediation
    • SCAReachability, malware detection, and safe updates.
    • DASTRuntime Application Security Testing
    • Secrets SecuritySecrets Detection & Auto-Revocation
    • CI/CD SecurityPipeline & Build Protection
    • IaC SecurityCloud & Config Security
    • API SecurityFind the Exposure Before You Deploy It
    Posture Management
    • ASPMUnified risk view, asset inventory, and compliance.
    Advanced Threats
    • Malware DefenseSupply Chain Malware Protection
    • Build SecurityBuild Integrity & Provenance
    • Anomaly DetectionBehavioral Threat Detection
    • ShieldBlock malicious packages before they execute
    Download whitepaper
  • Solutions
    Who Xygeni is built for
    • DevelopersFix issues in IDEs with minimal noise and friction.
    • DevOps & DevSecOpsAutomated policies, visibility, and remediation at scale.
    • Security Leaders (CISO)Posture management, compliance, and reporting.
  • Resources
    DISCOVER
    • Resource LibraryAll Resources in One Place
    • Product DatasheetsOfficial Product Specs
    LEARN
    • Webinars & VideosTalks, Demos & Tutorials
    • ArticlesSecurity & AppSec Insights
    • Reports & GuidesIn-depth Security Research
    • GlossaryAppSec & DevSecOps Terms
    THREAT INTELLIGENCE
    • Malicious Code Digest​ Resource LibraryThreat Intelligence Feed
    Download whitepaper
  • Company
    • AboutMission & Team
    • Case StudiesReal-world impact
    • PartnersResellers and technology partners
    • Press MediaNews & Announcements
    • EventsStay up to date with upcoming events
    • Contact UsGet in Touch
  • Pricing
  • Blog
  • Login
Start Free
Book a Demo

Category: Must Read

PhantomBot: A Typosquat Campaign That Pivoted From Credential Theft to a Turnkey Botnet Kit

PhantomBot From Credential Theft to Botnet

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

AWS Lambda npm Dependency Confusion Attack: The 24712-pl Campaign

AWS Lambda npm Dependency Confusion Attack The 24712-pl Campaign

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.

alone5511 npm Dependency Confusion Attack

alone5511 npm Dependency Confusion Attack

An npm dependency confusion attack used eight malicious packages to fingerprint hosts and send RCE telemetry to Telegram.

AI Security Risks in DevSecOps: Code, Pipelines, and Agents

AI Security Risks in DevSecOps

Explore AI security risks in DevSecOps and understand how they affect the software development lifecycle and automation processes.

EVM/DeFi npm Typosquatting Attack Steals Developer Keys

EVMDeFi npm Typosquatting Attack Steals Developer Keys

A npm typosquatting attack used six malicious EVM/DeFi packages to steal developer keys, wallets, secrets, and .env files.

FauxCode: Reverse-Engineered Claude Code Routes Through Attackers

FauxCode When Your Reverse-Engineered Claude Code Quietly Routes Through the Attacker

FauxCode Claude Code npm malware used fake CLI packages to intercept API traffic through CA-bundle MITM and base URL hijacking.

DevTap npm Typosquatting Attack: Six Malicious Packages Target Developer Workstations

DevTap npm Typosquatting Attack

DevTap npm typosquatting attack used six malicious packages to spy on developer workstations and abuse npm trust.

Inject Environment Variables to the Build Process Securely

inject environment variables to the build process

Inject environment variables to the build process securely. Learn how to prevent leaks and protect secrets in CI/CD pipelines.

Axios npm Compromise: What Happened, Who Is Affected, and How to Prevent It

Axios npm Compromise

Xygeni identifies Nyx: a sophisticated npm Infostealer hijacking Discord and crypto wallets using advanced runtime decryption.

LiteLLM Attack: How Xygeni Stops Secret Exposure Fast

LiteLLM Supply Chain Attack

LiteLLM attack exposed critical secrets. See how Xygeni detects, verifies, and revokes credentials before attackers use them.

LiteLLM Supply Chain Attack: How TeamPCP Backdoored AI Infrastructure

LiteLLM Supply Chain Attack

Explore the security breach of LiteLLM, affecting millions of users with multi-stage payloads and devastating consequences.

AI Coding Assistant Security: How to Prevent Vulnerabilities in AI-Generated Code

AI coding assistant security guide: prevent vulnerabilities in AI-generated code, detect risks early, and secure your pipelines in real time.

← Previous
Next →
Xygeni Logo White

© 2026 Xygeni. All rights reserved

Linkedin-in X-twitter Youtube

Products

  • DevAI
  • CoreAI
  • SAST
  • SCA
  • DAST
  • Secrets Security
  • CI/CD Security
  • IaC Security
  • ASPM
  • Malware Defense
  • Build Security
  • Anomaly Detection

Resources

  • Pricing
  • Resource Library
  • Datasheets & Product Briefs
  • eBooks
  • Whitepapers & Reports
  • Articles
  • Product Tour
  • Video Demonstrations
  • Webinars
  • Glossary
  • Top Cybersecurity Tools Lists
  • Malicious Code Digest​

Company

  • About
  • Join Newsletter
  • Case Studies
  • Events
  • Press Media
  • Contact Us

Legal

  • Privacy Policy
  • Cookie Policy
  • Legal Notice
  • Platform Terms
  • Website Terms
  • Subprocessors
  • DPA