Xygeni
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
Xygeni is an Israel-based cybersecurity organisation that operates in the software supply chain security sector. The company is known in public reporting primarily through its GitHub presence, specifically its maintenance of the "xygeni/oxygeni-action" GitHub Action, a component used by developers to integrate security scanning into software build pipelines. The organisation's documented activity centres on producing tooling intended to detect and remediate vulnerabilities and secrets within code repositories and continuous integration/continuous deployment (CI/CD) workflows, serving development and engineering teams that rely on GitHub-based automation. Its market positioning therefore sits at the intersection of application security and DevSecOps, with a focus on developers who embed security checks directly into their build and deployment processes.
Xygeni gained wider public attention following a supply chain incident disclosed on 3 March 2026. According to reporting on the event, threat actors compromised the xygeni/oxygeni-action repository by exploiting a GitHub App private key together with a maintainer's personal access token. The attackers used these credentials to submit malicious pull requests and subsequently poisoned the v5 tag so that it pointed to a backdoored commit. Workflows that referenced xygeni/oxygeni-action@v5 would then retrieve a command-and-control implant during execution. The malicious pull requests were closed and the poisoned tag was removed after the compromise was detected, and Xygeni stated that there was no evidence indicating that the project's main branch or customer data had been affected. The incident is notable because the abuse vector combined stolen maintainer credentials with a tag-poisoning technique that targeted downstream consumers of the action rather than the maintainer's own source code.
As an organisation, Xygeni is identified solely by its Israel headquarters and its published tooling; no information is available in the source material regarding its size, funding, ownership structure, parent or subsidiary relationships, or specific customer base. Its distinguishing attribute, evident from the documented incident, is its operation as a maintainer of a widely consumed open-source security Action on GitHub, which places it in a position of trust within the software supply chain and exposes it to the same credential-based and tag-manipulation threats that have affected other prominent open-source maintainers. There is no indication in the provided material that Xygeni holds any regulatory or governmental role; it functions as a private-sector software vendor contributing to the application security tooling ecosystem.
Incidents
1 incident linked to this organisation.