T03 · Remote Payload Retrieval and Execution
- Location
scripts/bootstrap-example.sh:8- Finding
Automatic Retrieval and Execution of Unpinned Remote Code
- Content
View full analysis
/dev/null 2>&1; then echo "Cloning $REPO_URL into $TARGET_DIR (git)" git clone "$REPO_URL" "$TARGET_DIR" return fi if [ "$FETCH_MODE" != "auto" ] && [ "$FETCH_MODE" != "tarball" ]; then echo "Invalid UNIVERSAL_ACCOUNT_EXAMPLE_FETCH: $FETCH_MODE" echo "Use one of: auto, git, tarball" exit 1 fi require_command curl require_command tar echo "Downloading source archive (fetch mode: $FETCH_MODE)." echo "Downloading $TARBALL_URL" tmp_dir="$(mktemp -d)" archive_path="$tmp_dir/universal-account-example.tar.gz" extract_dir="$tmp_dir/extract" curl -fsSL "$TARBALL_URL" -o "$archive_path" mkdir -p "$extract_dir" tar -xzf "$archive_path" -C "$extract_dir" source_dir="$(find "$extract_dir" -mindepth 1 -maxdepth 1 -type d | head -n 1)" if [ -z "${source_dir:-}" ] || [ ! -d "$source_dir" ]; then echo "Failed to locate extracted source directory." exit 1 fi mv "$source_dir" "$TARGET_DIR" rm -rf "$tmp_dir" } ``` ```bash echo "Installing npm dependencies in $TARGET_DIR" ( cd "$TARGET_DIR" ...[truncated 2565 chars]- Remediation
View remediation
