01The Lockfile Is a Crime Scene: Practical NPM Supply-Chain Triage
A practical workflow for investigating suspicious npm changes before they turn into a production incident.
10 min
xtra / index
Technical notes about security, software, systems, and the details worth keeping after an investigation or experiment.
01A practical workflow for investigating suspicious npm changes before they turn into a production incident.
02How to think about suspended, frozen, or starved security processes from a defender's point of view.
03A calm way to recognize, model, and solve small-state dynamic programming problems with masks.
04A journey from compilation errors to time limits to AC: how I optimized a LeetCode hard problem through iterative refinement.
Exploiting WerFaultSecure to suspend EDR and antimalware processes without BYOVD techniques.
06The Worm Returns: A Supply Chain Nightmare