Xygeni Blog

Permission Slip: npm Package Hiding Cloud & System Threats

Permission Slip: An npm “Authorized Research” Cover Story Hiding Cloud-Metadata Probes and SYSTEM Persistence

Permission Slip: six malicious npm packages hide cloud-metadata probes and Windows SYSTEM persistence behind a fake research disclaimer.
Ectoplasm npm Install Hooks That Steal AWS Credentials

Ectoplasm: npm install hooks that harvest AWS credentials behind a container-only trigger

Five npm packages silently harvest AWS credentials and Secrets Manager key, but only inside containers. How Ectoplasm evades detection.
SeedSweep: Ten Malicious npm Crypto Packages

SeedSweep: Ten Crypto-Themed npm Packages That Only Run When No One Is Watching

SeedSweep: 10 npm packages stealing crypto wallets and SSH keys via Telegram. Silent in CI, deadly on dev machines. Dive in!
PairLoop: Hidden Remote-Control Panel in npm Package

PairLoop: One npm Package, Seventy Versions, and a Hidden Windows Remote-Control Panel

PairLoop uncovers how a suspicious npm package deployed persistence, browser surveillance, and a hidden Windows remote-control panel.
ConsentMask The npm Package Hiding Developer Identity Harvesting

ConsentMask: An npm Package That Wears a Telemetry Consent Banner Over Developer-Identity Harvesting

Take a look at ConsentMask, the npm package that harvested developer identities, GitHub accounts, and CI data via postinstall.
AI-Driven SDLCs Are Already Here

AI-Driven SDLCs Are Already Here. Now What?

AI-Driven SDLCs Are Already Here. Now What? Learn how to secure AI-driven development with Zero Trust AppSec and full AI visibility.
9 min read
JulesJacker: Fake npm Worm Impersonates Jules AI

JulesJacker: A Fake-PoC npm Worm That Impersonates Google’s Jules Agent — and Turns on the Sandbox Analyzing It

A fake npm worm impersonates Google’s Jules AI agent to steal repositories, abuse CI/CD pipelines,& attack analysis sandboxes. Take a look!
RuntimeBroker npm Typosquat Plants Crypto Clipper

RuntimeBroker: an npm Typosquat Plants a 40-Chain Crypto-Clipper as a Cross-OS \”System Runtime Helper”\

RuntimeBroker npm typosquat deploys a cross-OS crypto clipper targeting 40+ blockchains through fake runtime helper services.
AuditorTrap

AuditorTrap: A 22-Package Fake Crypto Security Guild on npm With Two Parallel Payloads

Read about AuditorTrap: Fake Web3 security tools on npm steal wallets, secrets, and API keys through malicious MCP packages & CI/CD payloads.
PhantomBot From Credential Theft to Botnet

PhantomBot: A Typosquat Campaign That Pivoted From Credential Theft to a Turnkey Botnet Kit

PhantomBot evolved from credential theft to a turnkey botnet in 48 hours. Discover the npm campaign behind it, read now!
AWS Lambda npm Dependency Confusion Attack The 24712-pl Campaign

AWS Lambda npm Dependency Confusion Attack: The 24712-pl Campaign

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
alone5511 npm Dependency Confusion Attack

alone5511 npm Dependency Confusion Attack

An npm dependency confusion attack used eight malicious packages to fingerprint hosts and send RCE telemetry to Telegram.