Hey,

VinodJaspa

PhD Researcher & Full Stack Engineer

• AVAILABLE FOR WORK • OPEN TO OFFERS

Engineer &
Researcher

Vinod Jaspa
PhD · CS · Security

A simple story that reflects my curiosity!

My colleagues are continuously working in developer roles and earning good money. Some of them lack in-depth infrastructure knowledge, but they contribute every day by shipping products and keeping management happy.

I was also working as a developer with solid computer science knowledge. One day I noticed a huge number of security warnings being flagged directly by npm in the CLI. Most developers ignored them. Their priority was shipping the product and completing milestones.

I don't know why, but I chose to go deeper. I enrolled for a PhD and started analyzing those packages. I discovered vulnerabilities that could genuinely break real systems.

Today I am jobless while people who chose to keep management happy are earning decent salaries. So I ask myself — was my decision wrong? Am I a fool for caring about the community rather than myself? I don't have a complete answer yet. But I know one thing: the warnings were real. And someone had to read them.

I'm conducting research in the domain of supply chain attacks — one of the most critical and rapidly evolving areas in modern cybersecurity. My research investigates how adversaries compromise software supply chains and how we can defend against them.

Alongside my research, I'm a full-stack developer with 4+ years of production experience. I build systems with a security-first mindset — scalable, modular, and feature-rich by design. Every architectural decision I make is informed by my understanding of real-world attack vectors.

I love computer science deeply — not just as a career but as a lifelong curiosity. I write technical blogs, read voraciously, and spend hours brainstorming solutions to complex problems.

Quick LearnerSelf-TaughtSecurity-FirstProblem SolverTechnical WriterOpen SourceDeep ThinkerCS Enthusiast
4+Years Engineering
20+Projects Shipped
PhDIn Progress

Supply Chain
Attacks

01
Primary Research

Supply Chain Attack Vectors & Mitigation

Investigating how adversaries compromise software supply chains — from dependency poisoning and build system attacks to CI/CD pipeline vulnerabilities. Developing novel detection and mitigation frameworks for modern DevSecOps environments.

02
Threat Modeling

Dependency Poisoning

Analysis of malicious package injection into npm, PyPI and other public registries — including typosquatting, dependency confusion, and maintainer account takeovers.

03
CI/CD Security

Build Pipeline Integrity

Research into securing continuous integration pipelines against credential theft, malicious code injection, and tampered build artifacts at every stage.

Featured
Projects

01
Real-time Chat + Voice
Socket.ioWebRTCNode.jsFirebase
02
AI Integration Starter
OpenAIClaude APILangChainStreaming
03
Vector DB + LangChain RAG
pgvectorLangChain.jsPostgreSQLEmbeddings
04
Stripe Subscription System
Next.jsStripePostgreSQLAuth

Tools &
Technologies

Four years of building real products has sharpened my stack. I reach for the right tool for each job — always with security, performance, and maintainability in mind.

Frontend
React / Next.js
TypeScript
TailwindCSS
Animations
JavaScript
Vue.js
Angular
React Native
Android / iOS
Material UI / AntD
Backend
Node / Express
PostgreSQL
Firebase
MongoDB
Redis
Python / Flask
NestJS
Supabase
GraphQL
AI & Security
OpenAI / Claude
LangChain.js
Security Res.
Code Auditing
Penetration Testing
Threat Modeling
Vulnerability Mgmt.
MITRE ATT&CK
Docker / DevOps

Latest
Articles

Let's Work
Together

Available for freelance projects, research collaborations, consulting and full-time roles. Let's build something meaningful.