osj

Security engineer. Cloud focused. Still mostly just curious.

I work in cloud security during the day. Outside work, I usually end up pulling apart phishing kits, tracing delivery chains, mapping infrastructure, and writing down what the thread turns into.

This is where I keep the stuff I’m digging into: investigations, small tools, notes, and the occasional sample that’s too interesting to leave alone.

The short version

RoleSecurity Engineer
FocusCloud security, automation, infrastructure-heavy security work
ResearchPhishing infrastructure and delivery chain analysis
PatternFollow the weird thread until the bigger picture makes sense
Side hobbyBJJ

Investigations

Full archive →

★ Pinned research

npm Malware Cluster Uses Hidden README Payloads to Trigger Credential Theft

A suspicious npm package cluster using postinstall execution, credential scanning, hidden README payloads, and GitHub-based delivery attempts.


Tools

Want to trade notes or work on something?

I'm always down to talk shop.

probably hunting something