osj
Security engineer. Cloud focused.
Still mostly just curious.
I work in cloud security during the day. Outside work, I usually end up digging through software supply chain weirdness, tracing package behavior, mapping infrastructure, and writing down what the thread turns into.
This is where I keep the stuff I’m digging into: investigations, small tools, and the occasional sample that’s too interesting to leave alone.
The short version
Investigations
Archive →★ Pinned research
Same Loader, New Front Doors
Tracking a DPRK-associated npm loader across five delivery methods, from gist and SVG staging to jsonkeeper/stdin execution and a layered socket.io agent.
A Tiny npm Loader With a Much Bigger Payload
A five-stage npm postinstall chain that builds a local Node runtime, disguises an obfuscated implant as a VS Code manifest, and targets credentials, wallets, SSH material, and files.
npm Malware Cluster Uses Hidden README Payloads to Trigger Credential Theft
A suspicious npm package cluster using postinstall execution, credential scanning, hidden README payloads, and GitHub-based delivery attempts.
How My Homemade NPM Hunter Caught a Mini Shai-Hulud Package
A scheduled npm-hunter pipeline surfaced a Mini Shai-Hulud package and proved the lead generator was useful.
ClickFix: A Delivery Method to the Cookie Monster
Fake CAPTCHA, encrypted shellcode, and obfuscated .NET malware across an eight-layer delivery chain.
The Prince of Nigeria is Dead: AI Phishing Ops
A local AI model test showing how easily polished phishing copy can be generated without accounts, API keys, or external logs.
LinaStealer Unity NSIS Electron Loader: Multi-Stage Infostealer Campaign Analysis
Unity + NSIS + Electron duct-taped together. Creative, honestly.
Tools
Browse the real source of any published package — npm, PyPI, crates.io, or Go — right in the browser. Diff any two versions to see exactly what changed between releases. Nothing installs, nothing runs.
My private workbench for digging into suspicious packages and keeping the evidence, version diffs, and notes in one place.
Phishing email analyzer. Drop an .eml, get parsed headers, URLs, and a clean export.
Paste a GitHub Actions or GitLab CI file. Read the shape at a glance. Nothing runs.
Want to talk shop or work on something?
I'm always down to talk shop.