webPromedium

Lab 252 — BuildForge — RCE via npm Lifecycle Script Injection

hackadvisor

Task: CI/CD platform (Express.js) where users edit project package.json and trigger builds. Solution: inject shell commands via npm preinstall lifecycle script in a minimal package.json (no dependencies to avoid registry timeout), read flag from build logs.

$ ls tags/ techniques/
decoy_flag_recognitioncicd_pipeline_exploitationnpm_lifecycle_script_injectionpreinstall_script_abusebuild_log_exfiltrationminimal_package_json_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups