← All Challenges
Supply Chain Smoke
Forensics
200 pts
standard
Challenge Description
A production API started beaconing externally right after a routine dependency update. You must prove package-level compromise and trace where it entered the pipeline.
Find:
- Malicious package name.
- Malicious version.
- C2 domain contacted during build/runtime.
- Triggered lifecycle hook name.
Flag format: HackCTF{...}
Files
Hints
Submit Flag
Login to submit a flag.