
Malicious npm Package: Postinstall Infostealer
A developer at a software company runs a routine npm install and the terminal returns clean. Less than a minute later the web proxy records a large outbound upload from that workstation. Work the process tree, the file activity and the outbound traffic to reconstruct what the install actually did.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Brief: what happened on the build workstation
0Your team lead flagged a large outbound upload from Jordan’s workstation during a late-morning build run. Before you start pulling logs, get oriented on how a package install can become an execution event.
Identify the malicious package that triggered the hook
10Start by finding which package actually ran a postinstall script on this host. The proxy recorded the registry downloads for the install session; the file monitor recorded what landed on disk afterwards.
Identify what executed the postinstall script
10npm does not execute a postinstall script itself; it hands it to another program. Use the process tree to name the program that actually ran it. Give the bare file name, with no path.
Find the file the script staged on disk
15The script left one artefact of its own behind while it worked. Identify that file by name.
Pinpoint the exfiltration destination
15The material collected on the host did not stay there. Identify the destination it was sent to, using the proxy and DNS records.
Map the initial access to MITRE ATT&CK
10Close out by classifying how the attacker got code running on this host. Everything you need is in the four steps you have just worked.
6 tasks · 60 points total
Training Tools
Skills You'll Build
Ideal for newcomers to SOC operations. Guided investigation with clear indicators.
Prerequisites
- No prior experience required
- Familiarity with XDR concepts
- Familiarity with SIEM concepts
Ready to investigate?
More Operations
View allRemcos RAT: Malicious Invoice Attachment
An accounts-payable employee at Harwell Logistics opens what looks like an overdue supplier invoice, and minutes later her workstation is holding a persistent outbound session to an address outside the company on a port nothing else uses. Walk the mail gateway records, the endpoint file artifacts and the process tree in order, pulling one indicator out of each surface until the delivery, the loader, the execution chain and the implant are all named, then close the case with an ATT&CK label.
Account Takeover: Impossible-Travel Sign-In
A finance analyst's Microsoft Entra account is accessed without MFA from Moldova 18 minutes after their normal London sign-in. Impossible travel confirmed. The unauthorized session reads the inbox via Graph and adds an external recovery address. Work the Entra audit trail to identify the attacker IP, the compromised mailbox, and the persistence mechanism.
RDP Brute Force: Internet-Facing Server Login
An internet-exposed Windows Server running RDP has been receiving a sustained brute-force campaign from an external address. After dozens of failed authentication events, one attempt succeeds and an interactive session is opened. Reconstruct the attack from the Windows Security event log, identify the source and target, and classify the technique.