VinodJaspa
PhD Researcher & Full Stack Engineer
Engineer &
Researcher
A simple story that reflects my curiosity!
My colleagues are continuously working in developer roles and earning good money. Some of them lack in-depth infrastructure knowledge, but they contribute every day by shipping products and keeping management happy.
I was also working as a developer with solid computer science knowledge. One day I noticed a huge number of security warnings being flagged directly by npm in the CLI. Most developers ignored them. Their priority was shipping the product and completing milestones.
I don't know why, but I chose to go deeper. I enrolled for a PhD and started analyzing those packages. I discovered vulnerabilities that could genuinely break real systems.
Today I am jobless while people who chose to keep management happy are earning decent salaries. So I ask myself — was my decision wrong? Am I a fool for caring about the community rather than myself? I don't have a complete answer yet. But I know one thing: the warnings were real. And someone had to read them.
I'm conducting research in the domain of supply chain attacks — one of the most critical and rapidly evolving areas in modern cybersecurity. My research investigates how adversaries compromise software supply chains and how we can defend against them.
Alongside my research, I'm a full-stack developer with 4+ years of production experience. I build systems with a security-first mindset — scalable, modular, and feature-rich by design. Every architectural decision I make is informed by my understanding of real-world attack vectors.
I love computer science deeply — not just as a career but as a lifelong curiosity. I write technical blogs, read voraciously, and spend hours brainstorming solutions to complex problems.
Supply Chain
Attacks
Supply Chain Attack Vectors & Mitigation
Investigating how adversaries compromise software supply chains — from dependency poisoning and build system attacks to CI/CD pipeline vulnerabilities. Developing novel detection and mitigation frameworks for modern DevSecOps environments.
Dependency Poisoning
Analysis of malicious package injection into npm, PyPI and other public registries — including typosquatting, dependency confusion, and maintainer account takeovers.
Build Pipeline Integrity
Research into securing continuous integration pipelines against credential theft, malicious code injection, and tampered build artifacts at every stage.
Featured
Projects
Tools &
Technologies
Four years of building real products has sharpened my stack. I reach for the right tool for each job — always with security, performance, and maintainability in mind.
Latest
Articles
Let's Work
Together
Available for freelance projects, research collaborations, consulting and full-time roles. Let's build something meaningful.





