CyberXYZ Security Team

Security Research
& Threat Intel.

Analysis of supply-chain attacks, platform breaches, and emerging threats from the CyberXYZ detection engine.

All Posts

Research

Built for the AI Supply Chain: First to Block Go, and Secure AI Models

AI runs on PyPI, npm, Go, and model hubs. We watch all of them, read the source, and block at install.

Critical

binding.gyp: The npm Vector That Skips Postinstall

@immobiliarelabs Backstage plugins trojanized via a node-gyp command expansion. How the evasion works, the IOCs, and how to detect it.

Critical

Hades Campaign: PyPI Worm Hits AI and Bioinformatics Devs

A .pth startup hook runs a Bun-based credential stealer across 37 PyPI projects. Attack chain, verified IOCs, and hour-zero wave detection.

Critical

Mini Shai Hulud Returns: AntV npm Ecosystem Attack

TeamPCP pushed 639 malicious versions across 323 npm packages via the compromised account atool on May 19. Credential exfiltration, Sigstore forgery, and IOCs.

Critical

Vercel Security Incident: Context.ai OAuth Compromise

Full analysis of the Vercel breach via Context.ai OAuth compromise, including verified IOCs and remediation steps for affected teams.

Critical

Axios npm Attack: North Korean RAT via Compromised Maintainer

Malicious axios versions 1.14.1 and 0.30.4 deployed cross-platform RATs. Full IOCs, MITRE ATT&CK mapping, and remediation steps.

👋

Let's Talk

Want to learn how CyberXYZ protects your supply chain? We'd love to hear from you. Reach out and let's have a conversation.