Xygeni Blog

FauxUV: Fake PyPI uv Packages Open Jupyter to the Web

FauxUV: fake PyPI uv helpers that open an unauthenticated Jupyter server to the internet

FauxUV: fake PyPI uv helper packages install a passwordless JupyterLab server, then expose it to the internet via reverse tunnel.
Slopsquatting Attacks

Slopsquatting Attacks: How an AI Mistake Became a New Way Into Your Software Supply Chain

Slopsquatting attacks explained: how AI package hallucinations become real malware. See the evolution and practical prevention steps.
9 min read
forge-jsxy npm Infostealer: IOCs & Detection Guide

forge-jsxy: The npm Infostealer That Keeps Changing Its Name

Renamed npm infostealer forge-jsxy → pinokio-redis steals crypto wallets & credentials. IOCs, timeline, and defender guidance inside.
AI Triage and AutoFix

AI Triage and AutoFix: How to Actually Reduce Your Security Backlog

AI triage & AutoFix cut security backlogs by prioritizing what's exploitable and fixing it automatically. Here's how to make it work!
12 min read
GhostTracker: npm Trojan Rebranded in 74 Minutes — Same C2

GhostTracker: an npm trojan that rebranded within hours of takedown — and kept the same C2

GhostTracker rebranded 74 minutes after takedown, same C2, new names. Do you know how the npm trojan works and what to block first?
SkillLeak, Browser Credential Theft via MCP Skill

SkillLeak: A Browser-Credential Decryptor Delivered Through an MCP Skill

SkillLeak hides a Chrome/Edge password decryptor inside an MCP skill, not an install hook. Learn how it works and what defenders should check.
Zero Trust SDLC

Keys to use AI cybersecurity, Zero Trust SDLC, how to secure AI-generated code, AI Security

Zero Trust SDLC means securing what AI produces and uses. Learn the five surfaces, real attacks, and how to close the AI security gap now.
10 min read
ai inventory software

What Is an AI Inventory? A Practical Guide to AI Asset Discovery, AI-BOM and Shadow AI

What is an AI inventory? A practical guide to AI asset discovery, AI-BOM generation, shadow AI, and EU AI Act compliance.
DeviceDoor npm Package Shipping a Microsoft 365 Device-Code Phishing Framework

DeviceDoor: a public npm package shipping a Microsoft 365 device-code phishing and bulk-mail framework

DeviceDoor hides a device-code phishing framework inside an npm package. Learn how it works and how to defend against it.
secure software supply chain, ai bom, mcp security

OWASP Global AppSec EU 2026 Vienna: Key Takeaways on Secure Software Supply Chain, MCP Security, and the AI-BOM

OWASP Vienna 2026 recap: AISVS launch, MCP security gaps, AI-BOM readiness & what the industry is saying about secure software supply chain
5 min read
OWASP GLOBAL Appsec AI Security

AI Security at OWASP Global AppSec EU 2026: Meet Xygeni in Vienna

Xygeni is at OWASP Global AppSec EU 2026, Booth G-08. Live AI Security demos, Zero Trust SDLC, and the team in Vienna. Come by!
7 min read
CryptoDAO Confusion: npm Packages Harvesting CI/CD and Crypto Secrets

CryptoDAO Confusion: eleven npm packages, one payload, harvesting CI/CD and crypto-wallet secrets

CryptoDAO Confusion: eleven npm packages at version 99.99.99 harvesting CI/CD tokens, cloud keys, and crypto wallet secrets on postinstall.