T08 · Insecure Dependencies
- Location
scripts/monitor.sh:13- Finding
Automatic Installation of an Unpinned Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/monitor.sh, lines 13–17
Vulnerability Type: Supply-chain risk caused by runtime installation of an unpinned dependency
Risk Level: MediumComplete Code Snippet:
bash # Check whether psutil is installed if ! python3 -c "import psutil" 2>/dev/null; then echo "Installing psutil..." pip3 install psutil -q fiTechnical Analysis
The wrapper automatically invokes
pip3whenpsutilis unavailable. The installation command does not pin an audited package version, verify an integrity hash, select an explicitly trusted package repository, or require an isolated virtual environment.Package resolution therefore depends on the user's pip configuration, configured index URLs, network environment, and the package version available at execution time. If a configured package index, mirror, DNS/network path, or upstream release is compromised, executing the otherwise legitimate monitoring wrapper could install and run attacker-controlled code.
Python packages can execute build and installation logic during installation. A malicious package or compromised release may therefore execute code before the monitoring script starts. This finding concerns unsafe dependency acquisition; the reviewed project itself does not contain evidence that it intentionally retrieves a malicious package.
Attack Path
- An attacker compromises or controls a package source, mirror, or index configured for the victim's
pip3, or causes it to serve a maliciouspsutildistribution. - The victim runs
scripts/monitor.shin an environment wherepsutilcannot be imported. - The dependency check fails, causing the wrapper to execute
pip3 install psutil -q. - Pip resolves and downloads the attacker-controlled or compromised distribution without enforcing a reviewed version or expected hash.
- Malicious package installation or build logic executes with the privi ...[truncated 814 chars]
- An attacker compromises or controls a package source, mirror, or index configured for the victim's
- Remediation
View remediation
Remediation Suggestions
- Remove automatic package installation from the runtime wrapper. If
psutilis unavailable, terminate with a clear error and direct the operator to an explicit installation process. - Declare dependencies in a lock or requirements file using a reviewed, exact version rather than an unconstrained package name.
- Enforce distribution integrity with hashes, for example by using a hash-locked requirements file and
pip install --require-hashes. - Install dependencies into a dedicated virtual environment during a controlled deployment step instead of modifying the invoking user's global or shared Python environment.
- Use an explicitly configured, trusted package repository and secure transport. Restrict or audit pip configuration that can redirect dependency resolution to untrusted indexes.
- Incorporate dependency vulnerability and provenance checks into the release process, and update the pinned version through a reviewed procedure.
- Replace the installation block with a non-mutating dependency check, such as:
bash if ! python3 -c "import psutil" 2>/dev/null; then echo "Error: psutil is required. Install the audited, pinned dependency in an isolated environment." >&2 exit 1 fi- Remove automatic package installation from the runtime wrapper. If
