Chain Reaction | Axios Attack (TryHackMe)
On March 31, 2026, two malicious versions of Axios — one of JavaScript's most downloaded HTTP client libraries — were quietly pushed to npm and downloaded by developers across the globe. What followed

Search for a command to run...
Articles tagged with #python
On March 31, 2026, two malicious versions of Axios — one of JavaScript's most downloaded HTTP client libraries — were quietly pushed to npm and downloaded by developers across the globe. What followed

Plant Photographer is a TryHackMe challenge built around a botanist's personal portfolio website running on Werkzeug/Python. The box covers three main vulnerability classes: SSRF (Server-Side Request

Introduction Develpy is a beginner-friendly TryHackMe challenge that focuses on code injection and privilege escalation via cron job abuse. The attack surface starts with a custom Python 2 service r

This writeup covers a macOS Forensics: Artefacts challenge on TryHackMe involving the analysis of a 25GB disk image from a macOS 15.1.1 (Sequoia) system. The investigation required extracting user act

Introduction In 1899, Elbert Hubbard wrote a short essay that would outlive him by over a century. It told the story of Lt. Andrew Rowan, a soldier given one mission: deliver a message to General Garc

Python is one of the most versatile tools in a penetration tester's toolkit. Unlike purpose-built tools, Python gives you the flexibility to build custom solutions on the fly — tailored to the specifi
