Capture the Flag
Supply Chain Security CTF
A jeopardy-style CTF built entirely around software supply chain security. You don't read about dependency confusion or poisoned builds — you exploit and detect them, hands-on, against realistic targets.
The CTF runs on a dedicated portal
The last edition has ended. Watch this page for the next one.
How it works
No prior CTF experience required. The challenges teach the technique as you solve them.
Jeopardy-style
Independent challenges, each worth points that scale with difficulty. Solve what you can, in any order.
Solo or team
Play on your own or with a small team. Open to all skill levels — there are on-ramps for beginners.
On-site & online
Runs during Village events and on the CTF portal. Live status is shown on this page and across the site.
Challenge categories
Every category maps to a real way software supply chains get attacked and defended.
Dependency Confusion
Get a build to pull your package instead of the real one.
Typosquatting Detection
Spot the malicious look-alike hiding in a dependency tree.
CI/CD Pipeline Exploitation
Turn a misconfigured workflow into code execution.
SBOM & Provenance Forensics
Read a bill of materials and prove what really shipped.
Backdoor Detection
Find the planted logic inside an otherwise-normal package.
Supply Chain Forensics
Reconstruct a compromise from artifacts and logs.
Artifact & Signature Integrity
Break — or verify — signing and attestation flows.
Trust Erosion
Exploit the assumptions a build system makes about trust.
Registry & Package Security
Attack and defend the package registries themselves.
Author a challenge
The CTF takes community-authored challenges. If you have a supply-chain attack or detection worth turning into a puzzle, we want it.
New to the topic? Start with the talks & workshops or see everything on the activities page. Trophy and past winners live on people.