Skip to content
View 5h4d0wn1k's full-sized avatar
:dependabot:
Nothing is impossible for those who try
:dependabot:
Nothing is impossible for those who try

Block or report 5h4d0wn1k

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
5h4d0wn1k/README.md
Nikhil Nagpure Vulnerability Research & Coordinated Disclosure, Memory Safety & Fuzzing, Offensive Security Practitioner, AI/LLM Security Engineering, Hardware & Wireless Pentesting, 97 Merged Upstream PRs Profile views    Followers    249 repositories 1,025 stars    6 merged pull requests to independent open-source projects    License

LinkedIn-0A66C2?style=for-the GitHub-111827?style=for-the Portfolio-0891b2?style=for-the Profile last updated Email-EA4335?style=for-the


🛡️ About Me

Security engineer and vulnerability researcher. I find memory-safety and authorization-boundary defects in widely-deployed infrastructure — cluster control planes, network-facing daemons, and serialization libraries — and work with upstream maintainers and security response teams to get them fixed.

My work is evidence-first: every finding ships with a sanitizer transcript or a failing upstream test, a duplicate check, and a tested fix. Google has reviewed and publicly released one of my reports; another is in review with the Go project. 6 merged pull requests to independent open-source projects — Go, protobuf, SymPy, TheAlgorithms/Python, freeCodeCamp, free-programming-books — plus 57 merged across my own production and open-source organisations.

Alongside that I build and maintain the tooling — ~200 open-source offensive and defensive security tools, secure full-stack products, and hardware wireless kits — with a focus on systems that stay maintainable as they grow.

Identity Nikhil Nagpure · 5h4d0wn1k
🌍 Open to relocation & frequent travel · always exploring somewhere new
Education B.Tech CSE — Cybersecurity & Digital Forensics, VIT Bhopal (2021–2025) · CGPA 8.33/10
Now Technical Lead @ CuboidSoft · Founder @ Shadownik · Founding SWE @ Pawan Technologies
Previously: Offensive Security Intern @ InLighnX · Ethical Hacking Intern @ Internship Studio
Focus Vulnerability Research · Memory Safety · Fuzzing · Offensive Security · Red Teaming · API Security · AI/LLM Security · Hardware-Wireless Pentesting · Secure Full-Stack
Building ApiSecPlatform (enterprise API security testing) · Portable Wireless Pentest Toolkit (ESP32-based) · SentinelWall AI threat detection

Focus areas
Vulnerability Research-9f1239?style=flat-square Memory Safety-c026d3?style=flat-square Fuzzing-7c3aed?style=flat-square Offensive Security-red?style=flat Red Teaming-darkred?style=flat API Security-22d3ee?style=flat LLM Security-a21caf?style=flat Hardware & Wireless-14b8a6?style=flat Secure Full--Stack-eab308?style=flat

Core stack
Python-3776AB?style=flat TypeScript-3178C6?style=flat C++-00599C?style=flat Solidity-363636?style=flat Go-00ADD8?style=flat-square C-A8B9CC?style=flat-square Rust-000000?style=flat Dart-0175C2?style=flat SQL-4479A1?style=flat Java-E34F26?style=flat

Certifications
CEH-e63946?style=flat CNSP-457b9d?style=flat PEH (TCM)-6d6875?style=flat IELTS 7.5 (C1)-2a9d8f?style=flat

Communities
DEFCON Franklin Security-black?style=flat Cyber Expert - Ministry of Home Affairs (India)-1f5c8b?style=flat


🔬 Security Research & Vulnerability Disclosure

I research memory-safety and authorization-boundary defects in widely-deployed infrastructure — cluster control planes, network-facing daemons, and serialization libraries. The bar I hold: a finding is real when it reproduces under a sanitizer or fails an upstream unit test, and it ships with a tested fix. A theoretical attack scenario is not a finding.

Method: source audit of bounds/length handling → minimal reproducer → ASan/UBSan confirmation → duplicate check → private disclosure → verified fix.

Publicly disclosed work

protobuf-java
Google · gRPC
Integer-overflow and silent-truncation audit of Timestamps.parse in the Java ProtoJSON parser. Oversized timezone offsets overflow and wrap; >9 fractional digits are silently truncated — producing a different-but-valid Timestamp with no error, inconsistent with the C++ parser.

Issue #30276 · PR #30277 (+99/−10, awaiting review)
Reported to Google VRP (ref 567495093); Google reviewed it and released it for public disclosure.
Go stdlib
encoding/xml
xml.Marshal and EncodeToken emit ill-formed element and attribute names while returning a nil error — invalid XML leaves the encoder with no way for callers to detect it. Standard library, affects every Go program using encoding/xml.

Issue #81881 · CL 841865 (under review)

Also under private disclosure

Additional findings in Kubernetes admission control and embedded/network daemon memory safety are in coordinated private disclosure with the respective security response teams. Details are available on request once each advisory is published.

Disclosure policy: no finding is made public before the affected project has had a fair opportunity to ship a fix. Undisclosed reports are never discussed publicly, including here.


🧰 Tech Stack

Python-3776AB?style=for-the TypeScript-3178C6?style=for-the C++-00599C?style=for-the Solidity-363636?style=for-the Dart-0175C2?style=for-the Rust-000000?style=for-the Next.js-000000?style=for-the Linux-FCC624?style=for-the Docker-2496ED?style=for-the Offensive Security-22d3ee?style=for-the Hashcat-123456?style=for-the KaliLinux-557C94?style=for-the


🚀 Featured Projects

Project Description Stars
photo-organizer Local-first, private-by-default photo & video library — Rust daemon + Flutter desktop, SQLCipher vault, ChaCha20-Poly1305 encryption, OCR & scene search, P2P LAN sync Stars
Decentralized Cloud Storage Blockchain-backed decentralized storage — Solidity smart contracts sharing encrypted file references with on-chain access control Stars
ML Web-Attack Detection ML-powered web-attack detection — phishing URL, DoS intrusion & XSS classification Stars
cybersecurity-framework Interactive map of everything in cybersecurity — 27 domains, 776 categories, 1,067 curated offensive & defensive tools Stars
ApiSecPlatform Enterprise API security platform for automated testing, threat insights, and OWASP-aligned checks —
Portable Wireless Pentesting Toolkit ESP32-based field pentesting device for wireless assessments and protocol testing —

🧨 Flagship Security Toolchain (Shadow Kitchen)

The current effort — autonomous offensive/defensive security tooling for authorized labs. Every tool ships with docs, tests, and explicit legal-use boundaries.

Tool What it does
sentinelwall Autonomous AI network threat detection & correlation — MITRE ATT&CK mapping, ML anomaly detection, rule DSL, STIX/Navigator/HTML exports
mythicforge Adversarial LLM prompt-injection & jailbreak testing — 37 techniques, OWASP/NIST/MITRE ATLAS benchmarks, SARIF reports
shadowvault Cryptographic secrets lifecycle manager — AES-256-GCM vault, OPSEC zeroize, team RBAC, migration tools
hermesc2 C2 & post-exploitation research framework (lab) — listeners, stagers, beacons, encrypted transport, killswitch, offline loopback-only demo
viperstrike MCP (Model Context Protocol) server vulnerability auditor — AST/whitebox SAST for agentic AI tool handlers, SARIF-capable
crownjewel Cross-cloud identity federation auditor — Golden/Silver SAML, OAuth client-ID spoofing, OIDC validation, offline fixtures
aiarsenal Adversarial AI/ML security studio — data poisoning, model backdoors, extraction, membership inference, prompt injection, agentic red-team planner
webbreach OWASP Top-10 web exploitation framework — built-in localhost vulnerable targets, AI-guided scan queue
cloudpwn Cloud & container penetration suite — AWS/GCP/Azure enumeration, docker leaks, k8s secrets, terraform audit, CSPM
supplysec Supply-chain security gate — SBOM (CycloneDX/SPDX), offline advisory matching, policy gates, post-quantum scanning
toxindb RAG retrieval-time poisoning detector — canary injection, provenance attestation, SARIF+MD reports
honeynet Honeypot farm + deception grid — multi-protocol honeypots, attacker fingerprinting, dwell/risk scoring, quarantine

198+ catalog security tools and counting — see the security tool catalog. For more flagships: cryptocrack, grainrecon, exploitcraft, mobsek, endpointaegis, netpwn, wiair, socialforge, sprayshed, rogueai, postpwn, and the w/m/c/d/f/h/i/n/p/r/se/web/x/ai/cl coded series. All for authorized testing only.


👨‍💻 Experience

Technical Lead — CuboidSoft (Jan 2025 - Present)

  • Lead an IT software company delivering custom web applications, mobile apps, and digital solutions for SMEs and startups across multiple domains.
  • Lead full-stack architecture and development for client projects using Next.js, Node.js, PostgreSQL, and modern frontend frameworks to build secure, scalable applications.
  • Own development workflows end-to-end: Git version control, CI/CD pipelines, code reviews, and cloud/VPS deployment.
  • Ship on company strategy, branding, and go-to-market — service packaging, proposal writing, and technical client presentations.

Founder — Shadownik · Freelance Venture (Jun 2024 - Present)

  • Build and scale a multi-service freelance venture across cybersecurity, full-stack engineering, cloud deployment, and digital operations.
  • Deliver secure production systems and offensive security assessments for real-world clients.
  • Lead product development for ApiSecPlatform and multiple automation-focused services.

Founding SWE — Pawan Technologies (Sep 2025 - Feb 2026)

  • Developed responsive production web apps and scalable backend APIs.
  • Built integrations, database workflows, and cloud-ready deployment pipelines.

Offensive Cybersecurity Intern — InLighnX Global Pvt. Ltd. (Jun 2025 - Dec 2025)

  • Performed web application security assessments (OWASP Top 10, Burp Suite, Metasploit), threat modeling, and red-team simulations.
  • Contributed to large-scale IT infrastructure defense: intrusion detection monitoring, vulnerability triage, and security reporting.

Ethical Hacking Intern — Internship Studio (Nov 2023 - Dec 2023)

  • Identified and mitigated XSS vulnerabilities in production web applications; authored remediation reports.
  • Designed practical security lab environments simulating real-world attack scenarios.

🌍 Open Source Contributions

Contributions3,600+ in the last 12 months
Pull Requests237 authored · 177 merged · 6 merged to independent OSS · 57 merged to my own orgs
Repos on GitHub249 · 231 built from scratch · 1,025 stars
Organizations3 orgs · 20 repos (Shadownik · Cuboidsoft · CuboidPilot)

Independent open-source projects

Bugs found by reading the code, reproduced with a failing test, and fixed with a patch upstream maintainers can review and merge. These are the projects that accepted my work.

golang/go
Go standard library
xml.Marshal and EncodeToken emit ill-formed element and attribute names while returning nil error — callers get invalid XML with no way to detect it. Reached from every Go program using encoding/xml.
Issue #81881 · CL 841865
🟡 open — 3 comments, maintainer cross-linked the related family
protocolbuffers/protobuf
Google · gRPC
Integer overflow and silent truncation in Java ProtoJSON Timestamps.parse: oversized timezone offsets wrap, >9 fractional digits are dropped, and the parser returns a different but valid-looking Timestamp with no error — inconsistent with the C++ parser. Found via integer-overflow audit; fixed with tests.
Issue #30276 · PR #30277 (+99/−10)
🟡 open — mergeable, awaiting maintainer review. Google VRP released it for public disclosure.
SymPy solve returned solutions outside the domain of a denominator — e.g. x/log(x) returned complex and non-positive values that cannot satisfy the original equation, silently.
PR #30567
🟢 merged
TheAlgorithms/Python Made reversort and odd-even transposition sort generic over comparable items, so both work for any ordered type rather than int only — removing an artificial type restriction in two widely-copied algorithm implementations.
PR #15402 · PR #15405
🟢 both merged
freeCodeCamp Corrected a wrong truthy/falsy example and its wording in the JavaScript curriculum — a concept error in material used by millions of learners.
PR #70289
🟢 merged
EbookFoundation/
free-programming-books
Repaired dead turing.com.br links across the book lists by resolving them through the Wayback Machine.
PR #13472
🟢 merged

Open pull requests

Project Finding
pandas #69429 — GroupBy.agg with as_index=False and a MultiIndex column group produces a wrong result shape
scipy #26242 — sparse.csgraph mishandles duplicate CSR entries in bipartite matching

Professional open-source work

Beyond upstream contributions, 57 merged pull requests across organisations I build and maintain — CuboidSoft, CuboidPilot and TCM-ONE. This is production infrastructure work: removing leaked credentials from tracked git history, pinning third-party CI actions to immutable revisions, gating production deploys on domain test suites, reversible R2 shadow writes for account migration, and automated Android release delivery with a self-repairing rollback path. Listed separately because employer and owned repositories are not independent third-party review.


📊 GitHub Analytics

Profile Summary

GitHub statistics summary card Repositories per language summary card Most committed language summary card
Streak Stats
Contribution Heatmap

🏆 Certifications & Highlights

  • CEH (EC-Council)
  • CNSP (The SecOps Group)
  • Practical Ethical Hacking (TCM Security)
  • Patent filed: A Self-Cleaning Glasses Case System (Application No: 202421032123)

📬 Let's Connect

LinkedIn-0A66C2?style=for-the GitHub-111827?style=for-the Portfolio-0891b2?style=for-the Email-EA4335?style=for-the


"Build secure systems. Solve real problems. Create measurable impact."

Thanks for visiting

Pinned Loading

  1. photo-organizer photo-organizer Public

    Local-first, private-by-default photo & video library. Rust daemon + Flutter desktop with Android pairing; SQLCipher encryption, ChaCha20-Poly1305 vault, OCR & scene search, P2P LAN sync — all on-d…

    Dart 12 2

  2. Decentralized-cloud-storage Decentralized-cloud-storage Public

    Blockchain-backed decentralized storage prototype — Solidity smart contracts sharing encrypted file references with on-chain access control (Hardhat).

    Solidity 7

  3. A-Secure-Warning-Platform-From-Web-Attacks-Using-Machine-Learning A-Secure-Warning-Platform-From-Web-Attacks-Using-Machine-Learning Public

    Machine-learning web-attack detection platform for phishing URL, DoS intrusion, and XSS classification — scikit-learn + Flask labs.

    HTML 6