osj
Security engineer. Cloud focused.
Still mostly just curious.
I work in cloud security during the day. Outside work, I usually end up digging through software supply chain weirdness, tracing package behavior, mapping infrastructure, and writing down what the thread turns into.
This is where I keep the stuff I’m digging into: investigations, small tools, and the occasional sample that’s too interesting to leave alone.
The short version
Investigations
Archive →★ Pinned research
Same Loader, New Front Doors
Tracking a DPRK-associated npm loader across five delivery methods, from gist and SVG staging to jsonkeeper/stdin execution and a layered socket.io agent.
npm Malware Cluster Uses Hidden README Payloads to Trigger Credential Theft
A suspicious npm package cluster using postinstall execution, credential scanning, hidden README payloads, and GitHub-based delivery attempts.
How My Homemade NPM Hunter Caught a Mini Shai-Hulud Package
A scheduled npm-hunter pipeline surfaced a Mini Shai-Hulud package and proved the lead generator was useful.
ClickFix: A Delivery Method to the Cookie Monster
Fake CAPTCHA, encrypted shellcode, and obfuscated .NET malware across an eight-layer delivery chain.
The Prince of Nigeria is Dead: AI Phishing Ops
A local AI model test showing how easily polished phishing copy can be generated without accounts, API keys, or external logs.
LinaStealer Unity NSIS Electron Loader: Multi-Stage Infostealer Campaign Analysis
Unity + NSIS + Electron duct-taped together. Creative, honestly.
4 Firebase Projects, 410 Reply Addresses
What started as a pile of weird reply addresses turned into a pretty clear infrastructure story that kept leading back to one VPS.
Tools
Turn a suspicious package into an inspectable investigation. Artifactly preserves the exact artifact, extracts deterministic evidence, adds relevant threat intelligence, and keeps every claim linked to its source.

Browse the real source of any published package — npm, PyPI, crates.io, or Go — right in the browser. Diff any two versions to see exactly what changed between releases. Nothing installs, nothing runs.
Phishing email analyzer. Drop an .eml, get parsed headers, URLs, and a clean export.
Paste a GitHub Actions or GitLab CI file. Read the shape at a glance. Nothing runs.
Want to talk shop or work on something?
I'm always down to talk shop.