Blog
/
Authors
/
Roshan Piyush

Author Profile

Roshan Piyush

Sr. Principal Security Research Engineer

at
Harness

Roshan Piyush leads Security Research at Traceable by Harness and Aspen Labs, heading a team of developers-turned-researchers who build and ship security capabilities end-to-end. As a multidisciplinary expert, his work spans AI Security, Application & API Security, and Shift Left to Protect Right strategies. Roshan combines deep technical research with practical engineering to advance the modern application and AI security stack. He also contributes to open-source projects such as OWASP crAPI and Coraza WAF, and shares his insights through talks, tools, and community collaboration.

Latest from

Roshan Piyush

A pinned write-up worth starting with.

All posts by

Roshan Piyush

Technical

Shai-Hulud Miasma: Inside the Compromise of Red Hat’s Packages

An in-depth look at the Miasma supply chain attack that compromised Red Hat npm packages. Learn how the malware spread, stole credentials, abused trusted publishing, and the steps teams can take to mitigate risk.

Shai-Hulud Miasma: Inside the Compromise of Red Hat’s Packages
No items found.

Technical

Poisoning The Pipeline: How The Mastra AI Ecosystem Was Poisoned At The Registry Level

Learn how the Mastra AI supply chain attack poisoned npm packages, impacted AI pipelines, and how Harness SCS helps detect, block, and remediate compromised dependencies.

Poisoning The Pipeline: How The Mastra AI Ecosystem Was Poisoned At The Registry Level

Technical

Mini Shai-Hulud Explained: How the TanStack and RubyGems Supply Chain Attacks Worked

Mini Shai-Hulud is a self-propagating supply-chain worm targeting npm, PyPI, and RubyGems. It abuses CI/CD pipelines, stolen tokens, and trusted publishing flows to spread malicious packages and steal credentials.

Mini Shai-Hulud Explained: How the TanStack and RubyGems Supply Chain Attacks Worked

Technical

Shai-Hulud Miasma: Inside the Compromise of Red Hat’s Packages

An in-depth look at the Miasma supply chain attack that compromised Red Hat npm packages. Learn how the malware spread, stole credentials, abused trusted publishing, and the steps teams can take to mitigate risk.

Shai-Hulud Miasma: Inside the Compromise of Red Hat’s Packages

Technical

LiteLLM Compromise: Securing AI Pipelines from PyPI Supply Chain Attacks

LiteLLM PyPI was compromised in a supply chain attack, using .pth files and blockchain C2 to steal credentials and execute persistent, multi-stage malware.

LiteLLM Compromise: Securing AI Pipelines from PyPI Supply Chain Attacks
No items found.

More voices from the Harness team

Engineers, security leads, and platform folks worth following.

All authors