Postmortems, technical breakdowns, and the occasional bad day — published with the timeline, the evidence, and what we actually did about it. Not polished after the fact.
We kept pulling on the loader chain from part two. Strong evidence of remote shell and Python execution wrapped to run anywhere, a byte‑precise decryption puzzle we're still mid‑solve on, and a wall we hit on purpose rather than climb around.
The blockchain‑resolved C2 from part one looked like it might be a sinkhole or a taunt aimed at researchers. It wasn't. We confirmed it live, broke the encryption, and found a four‑stage loader chain underneath — all from isolated infrastructure, fetch‑only, nothing ever executed.
A collaborator's stolen GitHub credentials were used to quietly rewrite history across our account and a partner org's — planting a backdoor that finds its command server by reading transactions off the Ethereum blockchain. What it did, how we caught it, and how we undid it without cloning a single repo.
The public record of security work at Mojo Layers — incidents we've had, how we responded, and what we changed afterward. Written from the evidence, not from memory.
A vendor blog. No product pitches, no vulnerability marketing. If something happened to us, we're not spending the writeup convincing you to buy anything.