A comprehensive security assessment and penetration testing engagement designed to identify, exploit, and remediate critical vulnerabilities within a corporate network and external-facing web applications.
MessyAPI is a production-ready developer infrastructure platform I built to eliminate repetitive data utility work. It gives developers one API to clean, validate, match, transform, protect, and analyze messy data instead of rebuilding those capabilities for every application.
I designed the platform around real production requirements, including API-key authentication, tenant isolation, usage metering, rate limiting, idempotency, asynchronous jobs, retries, webhooks, observability, and secure data handling.
MessyAPI also includes JavaScript and Python SDKs, OpenAPI, MCP support, CLI tooling, RapidAPI integration, interactive testing, and composable workflows for chaining multiple data operations together.
The goal was simple: turn common data infrastructure developers repeatedly build themselves into one reliable API.
⚠️ Developers: Be careful with project files sent by “clients” or "recruiters".
I recently received a project from someone, who I reported instantly after looking at the malicious codebase. After inspecting the files, I discovered it was a malicious Git repository designed to target developers. I reported the person immediately.
The project looked like a normal Next.js/NestJS application, but the malicious code was hidden inside .git and related folders.
The attack was designed to trigger through normal developer workflows such as:
- git status, git checkout, or git commit
- VS Code/Cursor Git integrations
- AI coding agents that automatically inspect a repository
- Git hooks and other automated tooling
The payload appeared designed to retrieve additional encrypted programs from attacker-controlled infrastructure and execute them with the developer's permissions. The technique also showed characteristics reported in attacks targeting developers through fake freelance/job opportunities.
Important: I did not extract or execute the repository, and I inspected it in an isolated/read-only manner.
Protect yourself. Before opening an unfamiliar project:
- Don't blindly run npm install, git status, scripts, or other commands.
- Be extremely careful with .git, .github, .husky, .claude, and Git hooks.
- Don't open suspicious repositories directly in your normal development environment or AI coding agent.
- Verify who sent the project and why they need you to download it.
- If something feels suspicious, inspect the archive without extracting/executing it.
Don't assume a professional-looking codebase is safe. A developer's normal tools can become the attack surface.
SHA-256 of the archive:
94bc839a9876138b5bdeafdac068b43ece80b42eda240caff95a8e3a35b06a1f
Thanks for sharing this, Haris. Very important reminder, especially with freelance projects and recruiter links becoming a common attack vector. Definitely worth verifying the source before opening or running anything.
A sample SDET automation project demonstrating how a scalable web testing framework can be designed using Playwright, TypeScript, Page Object Model, API testing, and CI/CD.
The framework covers UI and API automation, reusable test components, cross-browser execution, smoke and regression suites, parallel test execution, and automated HTML reporting.
The project also demonstrates a GitHub Actions CI/CD pipeline that executes tests automatically, captures screenshots and logs, and publishes test reports for faster feedback.