
MaliciousBrowserExtensions
This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

InfectPE - Inject custom code into PE file [This project is not maintained anymore]

Real-time geospatial OSINT platform aggregating 60+ public telemetry feeds (ADS-B, AIS, satellites, CCTV) into a unified map with server-side recon…

Headless AI agent for deterministic reverse engineering.

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.

ioc2rpz is a place where threat intelligence meets DNS.

An LLM extension for Ghidra to enable AI assistance in RE.

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Rogue Binary Model Context Protocol (MCP): a Docker-packaged binary analysis lab for AI agents. It supports reverse engineering, malware triage, and…

CVE-2023-38831 is a Zero-day WinRAR vulnerability that lets attackers disguise malicious files in archives, tricking users into executing harmful…

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Inject malicious code into *.debs

Python Command-Line Ghidra MCP
