incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecurityhardSupply Chain PackageCritical asset
Scenario

Typosquat npm package `lodahs` beaconing during CI build — secrets at risk

A hard Cybersecurity scenario on Supply Chain Package.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · supply-chain-typosquat-lodahs

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Typosquat dependency triage
  • Developer-side supply-chain hygiene
MITRE ATT&CKmitre-attack
  • Supply Chain Compromise · Initial AccessT1195 · TA0001
    MappedHigh confidence

    Trains supply-chain triage when a developer installs a look-alike package.

MITRE D3FENDmitre-d3fend
  • File AnalysisD3-FA
    MappedHigh confidence

    Trains static-analysis triage of the suspicious dependency.

  • Service Binary VerificationD3-SBV
    MappedMedium confidence

    Trains binary-verification reasoning for developer-side components.

NIST CSF 2.0nist-csf-2
  • Supply Chain Risk Management · IdentifyID.SC · ID
    MappedHigh confidence

    Trains the supply-chain risk baseline the scenario centers on.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains dependency-level evidence triage.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains dependency-removal and key-rotation workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Hardware and Software Approval Process2.N
    MappedHigh confidence

    Trains the approval-process baseline that limits typosquat installs.

  • Vendor/Supplier Cybersecurity Requirements2.R
    MappedMedium confidence

    Trains the third-party requirements posture.

CIS Controls v8cis-controls
  • Application Software SecurityControl 16
    MappedHigh confidence

    Trains the application-software control the scenario exercises.

  • Service Provider ManagementControl 15
    MappedMedium confidence

    Trains the third-party provider control.