This is your work, valued

Australia

Paul McCarty

Elite
@6mile

Software Supply Chain Offensive Security. Vulnerability research and DevSecOps OG.

DevSecOps-Playbook. This is a step-by-step guide to implementing a DevSecOps program for any size organization

2k

gimmepatz. Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

43

undelete. This JavaScript CLI "undeletes' packages that have been removed from the NPM registry

33

nextjs-CVE-2025-29927. A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability

19

DEFCON33-Workshop. DEFCON 33 Workshop - Open Source Malware 101 - Everything you always wanted to know about npm malware (and more)

16

MALOSS. MALOSS scans package manifest files for malicious software packages and libraries

10

commit-audit. Shell script that checks if git commits are signed

10

super-confused. Super-confused is a next-gen dependency confusion tool.

10

git-hunter. Find threats in your source code

6

6mile. About me!

6

tvpo. Target, Value, Patterns and Objectives (TVPO) - A flexible threat modelling framework for the software supply chain

5

awesome-cicd-attacks. Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.

2

npm-increaser-downloads. A tool to promote your npm packages and boost their download counts through automated strategies.

2

awesome-api-security. A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.

2

ami_finder. Find your ami_id's for all regions for your products in the AWS Marketplace

2

panda-mirror. Identify what Chinese NPM mirrors are caching malicious packages

1

not-so-standard-package. Detection of Zero Hour Malicious Packages via ML

1

awesome-software-supply-chain-security. A compilation of resources in the software supply chain security domain, with emphasis on open source

1

CodeReviewWorkshop. Materials for "The Art of Finding Security Vulnerabilities in Code" workshop

1

CY4740FinalProject. Final Project for CY4740 Network Security

1

CloudShovel. A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where we scanned 20k+ public AMIs.

1

vps-attack-box. Generic Ubuntu or CentOS boxes built for offensive or OSINT work deployed in your favorite VPS provider

1

merlin. Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

1

OSCAR. A comprehensive, systematic and actionable way to understand attacker behaviors and techniques with respect to the software supply chain

1

BlackMass. A recon tool optimized for mass scanning

1

spdx-online-tools. Source for the website providing online SPDX tools

1

CloudFail. Python

1

threat-intel. Signatures and IoCs from public Volexity blog posts.

1

cloud-headers. This is a authoratative listing of all the HTTP headers used by the major cloud providers

1

shodan-dorks. How to search on the shodan.io website

1

Valid8Proxy. Tool designed for fetching, validating, and storing working proxies.

1

buildkite-agent. The Buildkite Agent is an open-source toolkit written in Go for securely running build jobs on any device or network

1

canary-packages. Canary packages are software packages that collect telemetry about who is analyzing software registries.

1

Bugcrowd-tech. Scraped Bugcrowd programs for techstack

1

aMALgamous. Shell and Pen-testing Tool

1

direktiv. Serverless Container Orchestration

1

hacktricks. Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

1

ossec_automation. bash scripts and puppet code to install/uninstall OSSEC

1

juicyinfo-nuclei-templates. Nuclei (https://github.com/projectdiscovery/nuclei) templates for extracting juicy info from web pages

1