CyberXYZ Security Team

Security Research
& Threat Intel.

Analysis of supply-chain attacks, platform breaches, and emerging threats from the CyberXYZ detection engine.

All Posts

Research

Built for the AI Supply Chain: First to Block Go, and Secure AI Models

AI runs on PyPI, npm, Go, and model hubs. We watch all of them, read the source, and block at install.

Critical

binding.gyp: The npm Vector That Skips Postinstall

@immobiliarelabs Backstage plugins trojanized via a node-gyp command expansion. How the evasion works, the IOCs, and how to detect it.

Critical

Hades Campaign: PyPI Worm Hits AI and Bioinformatics Devs

A .pth startup hook runs a Bun-based credential stealer across 37 PyPI projects. Attack chain, verified IOCs, and hour-zero wave detection.

Critical

Mini Shai Hulud Returns: AntV npm Ecosystem Attack

Maintainer token compromise pushed malicious versions into 42 npm packages on May 19. Credential exfiltration, Sigstore forgery, and IOCs.

Critical

Vercel Security Incident: Context.ai OAuth Compromise

Full analysis of the Vercel breach via Context.ai OAuth compromise, including verified IOCs and remediation steps for affected teams.

Critical

Axios npm Attack: North Korean RAT via Compromised Maintainer

Malicious axios versions 1.14.1 and 0.30.4 deployed cross-platform RATs. Full IOCs, MITRE ATT&CK mapping, and remediation steps.

Coming Soon

Supply-Chain Attack Patterns in 2026

A data-driven look at how supply-chain attacks evolved in 2026, covering dependency injection, typosquatting, and maintainer takeover trends.

Coming Soon

How CyberXYZ Detects Zero-Day Package Threats

Under the hood of six detection signals, dependency graph analysis, and behavioral modeling that catches malicious packages before install.

👋

Let's Talk

Want to learn how CyberXYZ protects your supply chain? We'd love to hear from you. Reach out and let's have a conversation.