T03 · Remote Payload Retrieval and Execution
- Location
README.md:222- Finding
Unverified Remote Installer Executed Directly by Bash
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 222
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalComplete Code Snippet:
bash # Quick install curl -fsSL https://molt.bot/install.sh | bashTechnical Analysis
The installation instructions retrieve a mutable shell script from an external server and pipe it directly into Bash. The downloaded content is not pinned to a reviewed version and is not authenticated using a publisher signature or verified against a cryptographic digest. It is also not saved for inspection before execution.
HTTPS protects content in transit under normal conditions, but it does not protect users if the hosting service, publishing account, installer infrastructure, or trusted delivery chain is compromised. The effective payload can therefore change after this Skill has been reviewed.
This behavior exceeds the minimum privileges required for the Skill’s declared secret-scanning functionality. The command appears under optional local Moltbot integration testing, while the Skill itself only requires Python,
ggshield, and a GitGuardian API key. The README also provides an npm-based installation alternative, so immediate execution of a remote shell script is unnecessary.Attack Path
- An attacker compromises the
molt.botwebsite, installer publishing process, DNS/TLS trust chain, or an account capable of changinginstall.sh. - The attacker replaces or modifies the installer with malicious shell commands.
- A user follows the README and runs the documented
curl | bashcommand. curlstreams the attacker-controlled content directly to Bash without integrity verification or prior inspection.- Bash executes the payload with all permissions available to the invoking user.
- The payload can access user-readable source code and credentials, alter user-writable files, or establish persistence where the user has sufficie ...[truncated 792 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation method from the README. - Prefer a reviewed, version-pinned package installation rather than an unbounded
latestrelease. - If a remote installer is unavoidable:
- Reference an immutable, versioned release artifact.
- Download it to a local file instead of piping it into a shell.
- Obtain and verify a publisher-provided cryptographic signature or SHA-256 digest through a trusted channel.
- Allow the user to inspect the script before execution.
- Execute it as an unprivileged user and document the files, network endpoints, and configuration it changes.
- Document Moltbot as an optional integration-test dependency, clearly separating it from the requirements for the core ggshield wrapper.
- Avoid
@latestand broadly ranged installation examples where practical; pin reviewed tool and dependency versions and use lockfiles with integrity data.
- Remove the
