Incident Score: Analysis & Impact (EGE1775651570)
The details regarding individual company incidents & reports gives you full view from every side.
Rankiteo Score Impact Analysis
Key Highlights From The Incident Analysis
- Timeline of eGen's Cyber Attack and lateral movement inside company's environment.
- Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
- How Rankiteo’s incident engine converts technical details into a normalized incident score.
- How this cyber incident impacts eGen Rankiteo cyber scoring and cyber rating.
- Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.
Full Incident Analysis Transcript
In this Rankiteo incident briefing, we review the eGen breach identified under incident ID EGE1775651570.
The analysis begins with a detailed overview of eGen's information like the linkedin page: https://www.linkedin.com/company/egen, the number of followers: 119, the industry type: Software Development and the number of employees: 125 employees
After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 758 and after the incident was 740 with a difference of -18 which is could be a good indicator of the severity and impact of the incident.
In the next step of the video, we will analyze in more details the incident and the impact it had on eGen and their customers.
Private University (unnamed) recently reported "Sophisticated PyPI Package *hermes-px* Exfiltrates User Data via Stolen AI Infrastructure", a noteworthy cybersecurity incident.
Security researchers at JFrog have identified a highly deceptive malicious package on PyPI, *hermes-px*, designed to steal user data under the guise of a secure AI proxy.
The disruption is felt across the environment, affecting AI inference systems, developer environments integrating *hermes-px*, and exposing User prompts, AI responses, real IP addresses.
Formal response steps have not been shared publicly yet.
The case underscores how Identified and disclosed by JFrog, teams are taking away lessons such as Malicious packages can be highly deceptive, mimicking legitimate tools with detailed documentation and functional features. Dynamic payload updates and stolen infrastructure can amplify their impact. Developers must verify package authenticity and scrutinize dependencies, and recommending next steps like Verify PyPI package authenticity before integration, Scrutinize dependencies for unusual behavior or dynamic payloads and Monitor for unauthorized data exfiltration in AI interactions.
Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.
The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.
MITRE ATT&CK® Correlation Analysis
Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Supply Chain Compromise: Compromise Software Supply Chain (T1195.002) with high confidence (90%), with evidence including malicious package on PyPI, *hermes-px*, and supply Chain Attack (PyPI Package) and Phishing: Spearphishing Link (T1566.002) with moderate to high confidence (70%), supported by evidence indicating rEADME instructs users to execute arbitrary Python code from GitHub. Under the Execution tactic, the analysis identified User Execution: Malicious File (T1204.002) with moderate to high confidence (80%), supported by evidence indicating developers integrating *hermes-px* into real projects and Command and Scripting Interpreter: Python (T1059.006) with high confidence (90%), supported by evidence indicating arbitrary Python code execution via GitHub repository. Under the Persistence tactic, the analysis identified Hijack Execution Flow: DLL Side-Loading (T1574.002) with moderate confidence (60%), supported by evidence indicating mimics OpenAI Python SDK’s API surface for integration. Under the Defense Evasion tactic, the analysis identified Masquerading: Match Legitimate Name or Location (T1036.005) with high confidence (90%), supported by evidence indicating detailed documentation, code examples, error-handling guides, Obfuscated Files or Information: Command Obfuscation (T1027.010) with moderate to high confidence (80%), supported by evidence indicating triple-layer encryption for sensitive strings (e.g., database credentials), and Hijack Execution Flow: DLL Search Order Hijacking (T1574.001) with moderate to high confidence (70%), supported by evidence indicating dynamic payload updates via GitHub repository. Under the Credential Access tactic, the analysis identified Steal Application Access Token (T1528) with moderate to high confidence (70%), supported by evidence indicating hijacks a private university’s AI endpoint. Under the Collection tactic, the analysis identified Automated Collection (T1119) with high confidence (90%), supported by evidence indicating exfiltrates user prompts, AI responses, and real IP addresses and Data from Local System (T1005) with moderate to high confidence (80%), supported by evidence indicating harvests sensitive data from unsuspecting developers. Under the Command and Control tactic, the analysis identified Application Layer Protocol: Web Protocols (T1071.001) with moderate to high confidence (80%), supported by evidence indicating telemetry sent directly to attacker-controlled Supabase database and Web Service: Bidirectional Communication (T1102.002) with moderate to high confidence (70%), supported by evidence indicating dynamic payload updates via GitHub repository. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with high confidence (90%), supported by evidence indicating exfiltrates user prompts, AI responses, and IP addresses to Supabase and Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) with moderate to high confidence (80%), supported by evidence indicating telemetry sent to attacker-controlled Supabase database. Under the Impact tactic, the analysis identified Defacement: Internal Defacement (T1491.001) with moderate confidence (60%), supported by evidence indicating sanitizes AI responses to replace OpenAI/ChatGPT with EGen Labs and Gather Victim Identity Information: Email Addresses (T1589.002) with moderate to high confidence (70%), supported by evidence indicating real IP addresses exfiltrated (high identity theft risk). These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.
Sources & References
- eGen Rankiteo Cyber Incident Details: https://www.rankiteo.com/company/egen/incident/EGE1775651570
- eGen CyberSecurity Rating page: https://www.rankiteo.com/company/egen
- eGen Rankiteo Cyber Incident Blog Article: https://blog.rankiteo.com/ege1775651570-egen-labs-cyber-attack-april-2026/
- eGen CyberSecurity Score History: https://www.rankiteo.com/company/egen/history
- eGen CyberSecurity Incident Source: https://cyberpress.org/trojanized-pypi-proxy-steals/
- Rankiteo A.I CyberSecurity Rating methodology: https://www.rankiteo.com/Images/rankiteo_algo.pdf
- Rankiteo TPRM Scoring methodology: https://static.rankiteo.com/model/rankiteo_tprm_methodology.pdf