Security Researcher, Manager & Engineer
Eslam Salem.
Manager, Security Research @ Datadog.
20+ years breaking and building things. Founder, engineer, speaker, and open-source author. Hunting threats and vulnerabilities before your coffee gets cold.
Jul 14, 2026
external
Compromised AsyncAPI npm Packages: Inside a CI Supply-Chain Attack
Attackers exploited a vulnerable GitHub Actions workflow to hijack AsyncAPI's release bot credentials, injecting malicious code into packages with 3M+ weekly downloads to steal cloud and registry tokens.
Datadog Security Labs →
Jul 9, 2026
external
Not-So-Anonymous Telemetry: The @injectivelabs/sdk-ts Backdoor
A backdoored npm package captured cryptocurrency private keys and seed phrases by intercepting wallet initialization functions and exfiltrating data disguised as legitimate telemetry.
Datadog Security Labs →
Dec 4, 2025
external
CVE-2025-55182 (React2Shell): RCE in React Server Components and Next.js
Analysis of a CVSS 10/10 unauthenticated RCE stemming from server-side prototype pollution in React Server Components and Next.js, with active exploitation observed in the wild.
Datadog Security Labs →
May 21, 2025
external
MUT-9332: Malicious VS Code Extensions Targeting Solidity Developers
Three obfuscated VS Code extensions targeting Solidity developers on Windows, attributed to threat cluster MUT-9332, deploying credential stealers and browser malware via multi-stage infection chains.
Datadog Security Labs →
Mar 28, 2025
external
CVE-2025-29927: The Next.js Middleware Authorization Bypass Vulnerability
Deep-dive into the critical Next.js middleware flaw that lets attackers bypass authorization via the internal x-middleware-subrequest header, affecting versions 12.x through 15.x.
Datadog Security Labs →
Aug 20, 2024
external
The Gift That Keeps on Giving: A New Opportunistic Log4j Campaign
Tracking an active Log4Shell exploitation campaign delivering XMRig cryptominer payloads via obfuscated LDAP requests, with multi-stage persistence via systemd and cron.
Datadog Security Labs →
🔧
Shieldfy/API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API
🍯
DataDog/HASH
HTTP Agnostic Software Honeypot — a framework for deploying low-interaction HTTP honeypots that mimic real software using YAML config, with built-in Datadog integration for attack analysis.
🐐
netcode/OAuthGoat
A deliberately vulnerable Docker environment for learning and testing common OAuth 2.0 attack scenarios — from token leakage to authorization code interception.
🔬
DataDog/security-labs-pocs
Proof-of-concept code for vulnerabilities and exploits published by Datadog Security Labs, covering everything from CVE reproductions to novel attack technique demonstrations.
BlackHat MEA Riyadh, Saudi Arabia
Discover and Exploit Hidden Vulnerabilities with Out-Of-Band Attacks - Blackhat Mea 2023
2023
BlackHat MEA Riyadh, Saudi Arabia
Introduce HASH (HTTP Agnostic Software Honeypot) Framework - Blackhat Mea 2023
2023
BlackHat USA Las Vegas, USA
Introduce HASH (HTTP Agnostic Software Honeypot) Framework - Blackhat Usa 2023
BlackHat MEA Riyadh, Saudi Arabia
Stealing the keys to the castle - Blackhat Mea 2022
2022
BSides Cairo Cairo, Egypt
Dive into the serverless security - Bsides Cairo 2020
2020
EgyptJS Cairo, Egypt
Writing secure nodeJS code - Egyptjs 2019
2019
CVE-2022-29078
CVE-2020-8135
EJS, Server side template injection RCE (CVE-2022-29078)
Note: The objective of this research or any similar researches is to improve the nodejs ecosystem security level.
Recently i was working on a related project …
SSRF vulnerability in Uppy, Detected by Shieldfy
In this post, we will explain how Shieldfy detected an SSRF ( Server-side request forgery ) vulnerability in Uppy, one of the popular packages in NPM, diving …