webPromedium

Lab 380 — BuildStream — RCE via Malicious npm Package Preinstall Script

hackadvisor

Task: CI/CD platform with internal npm registry where a project depends on a package not yet published. Solution: publish a malicious package with a preinstall script that reads /flag, then trigger the build pipeline to execute it and retrieve the flag from build logs.

$ ls tags/ techniques/
dependency_confusion_attacknpm_lifecycle_script_abusecicd_pipeline_exploitationunclaimed_package_hijacking

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups