AppSecNews
ASPM Commercial, free tier Growing

Xygeni

by Xygeni

A software supply chain security platform covering malicious package detection, pipeline and source control hardening, secrets, dependencies and code analysis.

Visit xygeni.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Xygeni in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • Language coverage per scanner type: verify against vendor documentation
  • Scope and limits of the free tier: confirm with vendor
  • Malicious package detection methodology and coverage of package ecosystems: verify

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Xygeni's centre of gravity is the software supply chain. Alongside conventional dependency analysis against advisory databases, it looks for malicious code in open source packages: install scripts that reach out to the network, obfuscated payloads, suspicious maintainer changes, typosquatted names, behavioral signals that separate a package that is compromised from one that is merely vulnerable. That is a different detection problem from CVE matching, and a meaningful one given how package registry attacks now work.

Around that it provides a broader set of checks: source control and CI configuration hardening, build anomaly detection, secret scanning, infrastructure-as-code analysis, static analysis of first-party code, SBOM generation and attestation against supply chain frameworks. Findings appear in one console correlated back to the repository and pipeline that produced them, which is the aggregation behavior placing the product in the posture management category rather than a single scanner niche.

Where it fits

It connects to source control and CI and can also run as a CLI in a pipeline step. Ownership is usually shared: pipeline hardening findings land with platform engineering, code and dependency findings with developers. It is most useful for organizations consuming a large volume of third-party packages across multiple ecosystems, where exposure to a compromised dependency is real and manual review is not happening.

Strengths

  • Malicious package detection addresses an attack pattern that advisory-database SCA structurally cannot see, since a fresh malicious release has no CVE.
  • Pipeline and source control posture checks cover the build system as an attack surface rather than only the code.
  • Broad capability coverage from one connection, with a CLI option for teams that prefer to drive scans from their own pipeline definitions.
  • SBOM and attestation output supports supply chain framework obligations without a separate tool.

Limitations

  • Breadth across many scanner types means depth in any single one, particularly static analysis of first-party code, is unlikely to match a specialist product.
  • Malicious package detection is inherently heuristic, so expect both false positives on unusual but legitimate packages and the possibility of missed novel techniques.
  • A smaller European vendor with less community documentation and fewer independent evaluations than the larger platforms, so budget time for a hands-on proof of concept rather than relying on published comparisons.

Who it suits

Sensible for engineering organizations with heavy open source consumption that have decided dependency compromise is a live risk, and for teams that want supply chain coverage and application scanning from one vendor. Less suitable for enterprises that already own deep specialist scanners and need an aggregation layer above them, since Xygeni is most valuable for what it detects itself rather than for what it ingests.

Used Xygeni? Recommend it under your own name and title.

Recommend this tool