Security Researcher, Manager & Engineer

Eslam Salem.

Manager, Security Research @ Datadog.
20+ years breaking and building things. Founder, engineer, speaker, and open-source author. Hunting threats and vulnerabilities before your coffee gets cold.

Security Researcher BlackHat Speaker Open Source Offensive Security Founder Cloud Security
Eslam Salem

// writing

view all →
Jul 14, 2026
external
Compromised AsyncAPI npm Packages: Inside a CI Supply-Chain Attack
Attackers exploited a vulnerable GitHub Actions workflow to hijack AsyncAPI's release bot credentials, injecting malicious code into packages with 3M+ weekly downloads to steal cloud and registry tokens.
Datadog Security Labs →
supply-chainnodejscloud
Jul 9, 2026
external
Not-So-Anonymous Telemetry: The @injectivelabs/sdk-ts Backdoor
A backdoored npm package captured cryptocurrency private keys and seed phrases by intercepting wallet initialization functions and exfiltrating data disguised as legitimate telemetry.
Datadog Security Labs →
supply-chainmalwarenodejs
Dec 4, 2025
external
CVE-2025-55182 (React2Shell): RCE in React Server Components and Next.js
Analysis of a CVSS 10/10 unauthenticated RCE stemming from server-side prototype pollution in React Server Components and Next.js, with active exploitation observed in the wild.
Datadog Security Labs →
cvercenodejsweb
May 21, 2025
external
MUT-9332: Malicious VS Code Extensions Targeting Solidity Developers
Three obfuscated VS Code extensions targeting Solidity developers on Windows, attributed to threat cluster MUT-9332, deploying credential stealers and browser malware via multi-stage infection chains.
Datadog Security Labs →
threat-researchsupply-chainmalware
Mar 28, 2025
external
CVE-2025-29927: The Next.js Middleware Authorization Bypass Vulnerability
Deep-dive into the critical Next.js middleware flaw that lets attackers bypass authorization via the internal x-middleware-subrequest header, affecting versions 12.x through 15.x.
Datadog Security Labs →
cvenodejswebpentesting
Aug 20, 2024
external
The Gift That Keeps on Giving: A New Opportunistic Log4j Campaign
Tracking an active Log4Shell exploitation campaign delivering XMRig cryptominer payloads via obfuscated LDAP requests, with multi-stage persistence via systemd and cron.
Datadog Security Labs →
threat-researchlog4jmalware

// conference_talks

view all →
BlackHat MEA Riyadh, Saudi Arabia
Discover and Exploit Hidden Vulnerabilities with Out-Of-Band Attacks - Blackhat Mea 2023
2023
BlackHat MEA Riyadh, Saudi Arabia
Introduce HASH (HTTP Agnostic Software Honeypot) Framework - Blackhat Mea 2023
2023
BlackHat USA Las Vegas, USA
Introduce HASH (HTTP Agnostic Software Honeypot) Framework - Blackhat Usa 2023
2023
BlackHat MEA Riyadh, Saudi Arabia
Stealing the keys to the castle - Blackhat Mea 2022
2022
BSides Cairo Cairo, Egypt
Dive into the serverless security - Bsides Cairo 2020
2020
EgyptJS Cairo, Egypt
Writing secure nodeJS code - Egyptjs 2019
2019