Skip to main content
Malicious npm Package: Postinstall Infostealer operation cover
BeginnerXDRSIEM

Malicious npm Package: Postinstall Infostealer

A developer at a software company runs a routine npm install and the terminal returns clean. Less than a minute later the web proxy records a large outbound upload from that workstation. Work the process tree, the file activity and the outbound traffic to reconstruct what the install actually did.

25m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Brief: what happened on the build workstation

0

Your team lead flagged a large outbound upload from Jordan’s workstation during a late-morning build run. Before you start pulling logs, get oriented on how a package install can become an execution event.

2

Identify the malicious package that triggered the hook

10

Start by finding which package actually ran a postinstall script on this host. The proxy recorded the registry downloads for the install session; the file monitor recorded what landed on disk afterwards.

SOC{package-name}Hint available
3

Identify what executed the postinstall script

10

npm does not execute a postinstall script itself; it hands it to another program. Use the process tree to name the program that actually ran it. Give the bare file name, with no path.

SOC{process.exe}Hint available
4

Find the file the script staged on disk

15

The script left one artefact of its own behind while it worked. Identify that file by name.

SOC{.filename}Hint available
5

Pinpoint the exfiltration destination

15

The material collected on the host did not stay there. Identify the destination it was sent to, using the proxy and DNS records.

SOC{hostname.domain.tld}Hint available
6

Map the initial access to MITRE ATT&CK

10

Close out by classifying how the attacker got code running on this host. Everything you need is in the four steps you have just worked.

SOC{Txxxx.xxx}Hint available

6 tasks · 60 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
XDR log analysis
SIEM log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with XDR concepts
  • Familiarity with SIEM concepts

Ready to investigate?

More Operations

View all