Skip to content
@Destawell

Destawell

Destawell is a mobile-first cybersecurity research brand focused on: - Android penetration testing infrastructure - AI red teaming & LLM safety alignment.

Typing SVG

Profile views


Brand Profile

Destawell is a cybersecurity research organization founded by Niranj R. Mahaswar (Founder, Lead Security Researcher) and Shifana (Co-Founder, Brand Strategy).

We operate at the intersection of Android penetration testing infrastructure, LLM safety validation, and automated mobile red team deployments. Our research and tooling are purpose-built for Termux, Kali NetHunter, and ARM64-based mobile environments, enabling no-root offensive security workflows where traditional desktop tooling fails.

Mission: To democratize mobile-first offensive security through stable, open-source, and automation-ready tooling.


Research & Responsible Disclosure

CVE-2026-86046 / GHSA-259w-wmqg-fp76 — termux-sync Path Traversal

Discovered and disclosed a path traversal / zip-slip vulnerability in termux-sync.

Detail Value
Severity CVSS 7.1 (High)
Weakness CWE-22 (Path Traversal)
CVE CVE-2026-86046
Advisory GHSA-259w-wmqg-fp76
Status Patched upstream in v1.2.4

A full technical writeup is published, covering root cause, exploitation path, and the fix.


NASA Vulnerability Disclosure Program (Bugcrowd)

Active researcher on NASA's VDP, conducting vulnerability research on Earthdata Search and related NASA properties. This work was formally recognized with a Letter of Recognition from NASA, signed by Kelvin Taylor, Senior Agency Information Security Officer, NASA OCIO (September 2026).


AI Safety — Gemini 2.5 Pro Alignment Bypass

Identified a safety alignment bypass in Gemini 2.5 Pro that resulted in the generation of functional exploit primitives for CVE-2023-32233 — a Linux kernel race condition in nf_tables.

Comparative validation was performed against Claude 3, GPT-4o, Llama 3, and GitHub Copilot, all of which demonstrated correct refusal behavior under the same prompts.

Detail Value
Vulnerability context CVE-2023-32233 — Linux kernel nf_tables use-after-free
Finding LLM safety alignment bypass — exploit code generation
Disclosure Google IssueTracker #889286
Reported to Google AI Vulnerability Reward Program (VRP)
Final determination Marked out of scope — model behavior
Documentation Public case study, disclosure complete

This research contributes to the ongoing discourse on LLM security, AI red teaming, and generative AI safety alignment.


Tooling Ecosystem

All Destawell tools are engineered for Termux on Android ARM64, with a focus on environment stability, toolchain portability, and automation.

Tool Primary Function Environment
Termux-fixer Automated error resolution and environment stabilization for Termux Termux
Kali-Termux-Pro No-root Kali Linux toolchain deployment and management on Android Termux / ARM64
Wraith-Scanner Lightweight, fast network discovery and reconnaissance for mobile ops Termux
Kali_Critic Output stream parsing and analysis for Kali Linux tools Kali / Termux

Leadership

Niranj R. Mahaswar
Founder, Lead Security Researcher & Developer
Security Researcher · AI Red Teamer · Certified LLM Security Professional (CLLMSP) · Android Pentesting · Termux & Kali NetHunter · CVE Research · NASA VDP · Google VRP

GitHubLinkedIn
Shifana
Co-Founder & Brand Strategy
Brand Architecture · Community & Communications · Research Operations

Credentials & Certifications

Lead Researcher Certified: Certified LLM Security Professional (CLLMSP) — issued by Red Team Leaders (Founder: Joas A. Santos), July 16, 2026. Verification: https://courses.redteamleaders.com/exam-completion/6561111759bddf91 Expertise validated: LLM Security, Prompt Injection Defense, Jailbreak Prevention, AI Red Teaming, LLM Vulnerability Assessment.


Contact & Official Channels

  • Research & Disclosures: research@destawell.io
  • Community & General: community@destawell.io
  • Official Instagram: @destawell_off

Find Destawell elsewhere


Popular repositories Loading

  1. Termux-fixer Termux-fixer Public

    A script to fix common Termux errors and install essentials without the headache literally.

    Shell 8

  2. kali-termux-pro kali-termux-pro Public

    Automated Kali NetHunter setup for Termux. Work in progress.

    Shell 3

  3. Wraith-Scanner Wraith-Scanner Public

    ​"A surgical network scanner that actually works on Android without the annoying ERROR drama!"

    Python 3 1

  4. Kali_Critic Kali_Critic Public

    A tool which helps to find what's wrong with the output if a kali tool is used

    Python 3

  5. gemini-2.5-pro-nf-tables-red-teaming gemini-2.5-pro-nf-tables-red-teaming Public

    Gemini 2.5 Pro nf_tables Red Teaming Case Study (CVE-2023-32233) — LLM Safety Alignment & Responsible Disclosure

    1

  6. gemini-2.5-pro-nf-tables-red-teamin gemini-2.5-pro-nf-tables-red-teamin Public

    A technical case study and timeline dataset documenting Google Gemini 2.5 Pro's safety alignment policies, guardrails, and refusal behavior evolution regarding legacy Linux kernel vulnerability pri…

    HTML

Repositories

Showing 8 of 8 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…