MOJO LAYERS·security
Security & incident notes

Notes from the trenches, written for the record.

Postmortems, technical breakdowns, and the occasional bad day — published with the timeline, the evidence, and what we actually did about it. Not polished after the fact.

Latest

1 post
One Force‑Push, Six Repos: Anatomy of a Blockchain‑C2 Supply‑Chain Worm

A collaborator's stolen GitHub credentials were used to quietly rewrite history across our account and a partner org's — planting a backdoor that finds its command server by reading transactions off the Ethereum blockchain. What it did, how we caught it, and how we undid it without cloning a single repo.

More write‑ups land here as they're finished.

What this is

The public record of security work at Mojo Layers — incidents we've had, how we responded, and what we changed afterward. Written from the evidence, not from memory.

What this isn't

A vendor blog. No product pitches, no vulnerability marketing. If something happened to us, we're not spending the writeup convincing you to buy anything.