The first Enterprise Season continues the ACT II: Proxy Crown with a new Sherlock, Relay of Deceit.
This time, the focus shifts to the software supply chain. Hidden inside what appears to be a legitimate npm package is malicious code designed to evade review, perform host reconnaissance, and quietly exfiltrate sensitive data over DNS.
Players will practice how to:
  • Analyze npm packages safely without executing untrusted code
  • Uncover malicious behavior hidden in JavaScript
  • Investigate covert DNS-based communication
  • Reconstruct attacker activity from network traffic
  • Assess the impact of a software supply-chain compromise
Relay of Deceit