osj

Security engineer. Cloud focused. Still mostly just curious.

I work in cloud security during the day. Outside work, I usually end up digging through software supply chain weirdness, tracing package behavior, mapping infrastructure, and writing down what the thread turns into.

This is where I keep the stuff I’m digging into: investigations, small tools, and the occasional sample that’s too interesting to leave alone.

The short version

RoleSecurity Engineer
FocusCloud security, automation, infrastructure-heavy security work
ResearchPhishing infrastructure and delivery chain analysis
PatternFollow the weird thread until the bigger picture makes sense
Side hobbyBJJ

Investigations

Archive →

★ Pinned research

Same Loader, New Front Doors

Tracking a DPRK-associated npm loader across five delivery methods, from gist and SVG staging to jsonkeeper/stdin execution and a layered socket.io agent.


Tools

Want to talk shop or work on something?

I'm always down to talk shop.

probably hunting something