Skip to content

Blog

Long-form writing on DevOps and security engineering — incidents, post-mortems, and the parts of infrastructure work that only show up under pressure. For project write-ups with measured outcomes, see the case studies.

Anatomy of a Two-Stage Supply-Chain Worm

35 repos in 54 minutes

One trojaned public repository compromised a developer laptop. Sixty-four days later, the stolen GitHub token was used to inject malware into 35 repositories in 54 minutes. Full timeline, both injection vectors, the commit-forgery tells, blockchain-resolved C2, verbatim IOCs — and the four conclusions the investigation got wrong before it got it right.

SecuritySupply ChainIncident ResponseGitHub
Read the post →