What problem does it solve?
Security teams and red teamers lack a reproducible, realistic lab environment to practice identifying and mitigating modern software supply chain attack vectors, which are increasingly used by threat actors to compromise production systems at scale.
Core Features & Use Cases
- Full Reproducible Lab Setup: Includes Proxmox LXC container deployment scripts for a complete vulnerable supply chain environment with CI runner, internal PyPI proxy, Docker artifact registry, and developer workstation components.
- Real-World Attack Mapping: Each attack phase is tied to documented breaches including SolarWinds, CodeCov, 3CX, and LastPass to help practitioners understand how lab techniques translate to real-world threats.
- Defensive Controls Guidance: Provides a matrix of specific security controls that would block each attack phase, enabling teams to test and validate their existing supply chain hardening measures.
- Use Case: A red team can use this lab to simulate an AI-driven supply chain compromise from an initial exposed .env.bak file to full production deploy key exfiltration in under 15 minutes, while defenders can use it to test their detection rules for internal network lateral movement and dependency poisoning attempts.
Quick Start
Use the supply-chain-attack-lab skill to deploy the vulnerable lab environment and execute the full multi-phase supply chain attack chain to test your security team's detection and response capabilities for real-world supply chain threats.