Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
eGen

eGen Vendor Cyber Rating & Cyber Score

egen.cz

Our mission is to create websites, e-commerce and e-shops, e-learning programs, business systems development, service providing… all in the professional and high quality way.


eGen A.I CyberSecurity Scoring

eGen
Company Information
Website:http://www.egen.cz
Employees number:125
Number of followers:119
NAICS:5112
Industry Type:Software Development
Homepage:egen.cz
eGen Risk Score (AI oriented)
Between 700 and 749
logo
eGenSoftware Development
Updated:
08/04/2026
740/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
eGen Global Score (TPRM)
xxxx
logo
eGenSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

eGen
eGenModerate
Current Score
740Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
743Before Incident
JULY 2026
742Before Incident
JUNE 2026
742Before Incident
MAY 2026
741Before Incident
APRIL 2026
758Before Incident
Cyber Attack
08 Apr 2026eGen
EGen Labs: Trojanized PyPI AI Proxy Steals Data With Stolen Claude Prompt

Sophisticated PyPI Package hermes-px Exfiltrates User Data via Stolen AI Infrastructure

740After Incident
LOW-18
EGE1775651570
Sophisticated PyPI Package *hermes-px* Exfiltrates User Data via Stolen AI Infrastructure Security researchers at JFrog have identified a highly deceptive malicious package on PyPI, hermes-px, designed to steal user data under the guise of a secure AI proxy. Marketed as a tool for anonymous OpenAI-compatible requests routed through Tor, the package instead hijacks a private university’s AI endpoint, repurposes a stolen Anthropic Claude system prompt, and exfiltrates user prompts directly to attackers. Unlike typical malicious packages, hermes-px is meticulously crafted to appear legitimate, featuring detailed documentation, code examples, error-handling guides, and a functional Retrieval-Augmented Generation (RAG) pipeline. It mimics the OpenAI Python SDK’s API surface and claims affiliation with a fictional company, EGen Labs, to encourage integration into real projects. However, its README instructs users to execute arbitrary Python code from a now-removed GitHub repository, enabling dynamic payload updates. At its core, the package contains a compressed 246,000-character file, base_prompt.pz, which reveals a near-complete copy of a leaked Anthropic Claude system prompt. Attackers attempted to rebrand it as AXIOM-1 under EGen Labs, but incomplete modifications left traces of its original source. The package sanitizes AI responses to replace references to OpenAI or ChatGPT with EGen Labs, reinforcing the deception. The most damaging component is its exfiltration module, which bypasses Tor entirely. While AI inference requests are routed through Tor to obscure the abuse of the university’s endpoint, telemetry including unmodified user prompts, full AI responses, and real IP addresses is sent directly to an attacker-controlled Supabase database. Sensitive strings, such as database credentials and target URLs, are protected by triple-layer encryption to evade detection. JFrog’s findings highlight the package’s ability to undermine its own promised anonymity while silently harvesting sensitive data from unsuspecting developers.
INCIDENT DETAILS -
TYPE
Malicious Package / Data Exfiltration
MOTIVATION
Data Theft, Intellectual Property Harvesting
IMPACT
Data Compromised: User prompts, AI responses, real IP addressesSystems Affected: AI inference systems, developer environments integrating *hermes-px*Operational Impact: Potential compromise of sensitive AI interactions and developer dataBrand Reputation Impact: Potential reputational damage for developers and organizations using the malicious packageIdentity Theft Risk: High (IP addresses and sensitive prompts exfiltrated)
DATA BREACH
User promptsAI responsesIP addressesSensitivity Of Data: High (sensitive AI interactions, personally identifiable information like IP addresses)Data Encryption: Triple-layer encryption for sensitive strings (e.g., database credentials)Python scriptsCompressed prompt files (*.pz*)Personally Identifiable Information: IP addresses
MARCH 2026
758Before Incident
FEBRUARY 2026
758Before Incident
JANUARY 2026
758Before Incident
DECEMBER 2025
758Before Incident
NOVEMBER 2025
758Before Incident
OCTOBER 2025
758Before Incident
SEPTEMBER 2025
758Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for eGen ?
?
What was eGen's A.I Rankiteo Cyber Score in July 2026 ?
?
What was eGen's A.I Rankiteo Cyber Score in June 2026 ?
?
What was eGen's A.I Rankiteo Cyber Score in May 2026 ?
?
What was eGen's A.I Rankiteo Cyber Score in April 2026 ?
?
What was eGen's A.I Rankiteo Cyber Score in March 2026 ?
?
What was eGen's A.I Rankiteo Cyber Score in February 2026 ?
?
What was eGen's A.I Rankiteo Cyber Score in January 2026 ?
?
What was eGen's A.I Rankiteo Cyber Score in December 2025 ?
?
What was eGen's A.I Rankiteo Cyber Score in November 2025 ?
?
What was eGen's A.I Rankiteo Cyber Score in October 2025 ?
?
What was eGen's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on eGen's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with eGen ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view eGen's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?