CRTO // Security Researcher // Developer

ikarus981

_
$ cat certs.txt
[CRTO] Certified Red Team Operator - Zero Point Security
[CRTE] Certified Red Team Expert - Altered Security
 
$ cat about.md
Obsessed with offensive security. I build tools,
hunt vulnerabilities, and defeat defenses better.
 
$ ls projects/
npm-c2/ C2 channel using npm registry dist-tags
 
$ cat research.log
[found] XSS on UCLM intranet - disclosed via Open Bug Bounty
Projects

What I've Built

npm

npm-c2

C2 channel that uses npm registry as communication infrastructure for red team operations. Implements serverless architecture leveraging whitelisted legitimate services. Features Python CLI operator with XOR-encrypted npm tokens, implant compiled as Node.js-masquerading EXE via PyInstaller, and dist-tag protocol with base64url encoding for commands. Communicates via HTTPS to npmjs.org with advanced OPSEC: credential obfuscation, gaussian jitter polling (60-80s), tags simulating CI/CD builds, and local state management. Demonstrates why trusted services become persistence vectors, teaching defensive teams to detect anomalies in legitimate traffic. Standalone implant generator, multi-architecture support (x64, ARM64, IA32), and file operations. Active development with evasion improvements. Listed on lolc2 registry.

Python npm C2 PyInstaller

Vulnerability Research

Findings

Open Bug Bounty // XSS

Cross-Site Scripting on UCLM Intranet

Stored XSS vulnerability discovered on the intranet portal of Universidad de Castilla-La Mancha. Reported and disclosed through Open Bug Bounty.

View Report
Tooling // C2

npm-c2: C2 Over Package Registries

C2 channel using npm registry dist-tags as the transport layer. Listed on the lolc2 project registry as a living-off-the-land C2 technique.

View Project

Expertise

Areas of Interest

Web

Web Application Security

Black-box and white-box testing of web applications, APIs, and microservices. Focus on XSS, SSRF, injection flaws, and auth bypasses.

OWASPXSSSSRFAPI
C2

C2 Development

Building custom C2 channels over unconventional protocols - npm registries, DNS, and other trusted services. Focus on OPSEC and evasion.

PythonAV BypassEDROPSEC
AD

Active Directory

Enumeration and exploitation of Active Directory environments: Kerberoasting, AS-REP roasting, delegation abuse and lateral movement across the domain.

KerberosBloodHoundImpacketPivoting
RF

Wireless Security

Wireless network security auditing: WPA2/3 assessment, rogue AP detection, deauthentication attacks, and enterprise 802.1X misconfiguration testing.

WPA2/3WPSAirgeddonPixie
SH

System Hardening

Security hardening and defensive configuration across the stack: Active Directory lockdown, Docker container security, web server reinforcement (Nginx, Apache), WordPress auditing, and OS-level hardening.

ADDockerWordPressLinux

Get in Touch

Have a question about npm-c2, want to report a bug, or just want to connect?

LinkedIn