[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNPlZFIXDqK5pWNu6WTBwsGzWCO_uL3mIaTnv6a8G78E":3},{"article":4,"iocs":31,"watch_terms":38},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":10,"entities":15,"category_id":16,"category":17,"article_tags":20},"6798b2a4-27ba-46d9-8845-2dc0b920309b","Xygeni GitHub Action Compromised Via Tag Poison","xygeni-github-action-compromised-via-tag-poison","Attackers operated an active C2 implant for up to a week and compromised AppSec vendor Xygeni's xygeni\u002Fxygeni-action in that time.","Attackers compromised the Xygeni GitHub Action repository through tag poisoning, maintaining an active command and control implant for up to a week. The attack targeted the xygeni\u002Fxygeni-action package, a supply chain component used by developers for application security scanning. This incident demonstrates a critical risk in GitHub-based dependency distribution where malicious versions can reach dependent projects.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fapplication-security\u002Fxygeni-github-action-compromised-via-tag-poison","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fbltca84dfe5b302bfeb\u002F69b1c687e135793785e83b40\u002FLock_unlock_graphic_Pattara_Alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-03-11T20:22:39+00:00","2026-03-14T09:41:10.370894+00:00",[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":16,"icon":10,"name":18,"slug":19},"Supply Chain","supply-chain",[21,26],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":27},{"id":28,"icon":10,"name":29,"slug":30},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[32,35],{"type":25,"value":33,"context":34},"xygeni\u002Fxygeni-action C2 implant","Active command and control implant maintained in compromised GitHub Action for up to 7 days",{"type":25,"value":36,"context":37},"tag poison attack","Supply chain attack vector used to compromise Xygeni's GitHub Action repository",[]]