T03 · Remote Payload Retrieval and Execution
- Location
scripts/install-bbdown.js:34- Finding
Automatic Retrieval and Execution of an Unverified Third-Party Binary
- Content
View full analysis
Vulnerability Details
File Location:
package.json:12-14;scripts/install-bbdown.js:34-52, 61-70, 84-104
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: HighVulnerable Code
json "scripts": { "test": "node tests/", "start": "node bin/bilibit.js", "postinstall": "node scripts/install-bbdown.js" }js if (platform === 'darwin') { if (arch === 'arm64') { downloadUrl = 'https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_macos-arm64.zip'; } else { downloadUrl = 'https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_macos-x64.zip'; } } else if (platform === 'linux') { if (arch === 'arm64') { downloadUrl = 'https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-arm64.zip'; } else { downloadUrl = 'https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_linux-x64.zip'; } } else if (platform === 'win32') { binaryName = 'BBDown.exe'; downloadUrl = 'https://github.com/nilaoda/BBDown/releases/download/1.6.3/BBDown_1.6.3_20240814_win-x64.zip'; }js const installDir = path.join(__dirname, '..', 'node_modules', '.bin'); const zipPath = path.join(installDir, 'bbdown.zip'); const curl = spawn('curl', ['-L', '-o', zipPath, downloadUrl], { stdio: 'ignore' }); const unzip = spawn('unzip', ['-o', '-q', zipPath, '-d', installDir], { stdio: 'ignore' }); const installPath = path.join(installDir, binaryName); if (!fs.existsSync(installPath)) { console.log('❌ 解压后未找到 BBDown 二进制文件'); console.log('安装目录内容:', fs.readdirSync(installDir)); resolve(false); return; } fs.chmodSync(installPath, '755');Technical Analysis
The npm
postinstalllifecycle automatically downloads a platform-specific BBDown archive, extracts it into the package's executable directory, and m ...[truncated 2344 chars]- Remediation
View remediation
Remediation Suggestions
- Publish a trusted manifest containing a distinct SHA-256 or stronger digest for every supported archive.
- Embed or securely pin those expected digests in the reviewed npm package and verify the downloaded bytes before extraction.
- Fail closed and delete the archive if verification fails. Never make an unverified file executable.
- Verify a signed release manifest or platform-native code signature against a pinned publisher identity where available.
- Restrict redirects to an explicit allowlist of HTTPS hosts, or avoid unrestricted
curl -L. - Validate every archive entry before extraction and reject absolute paths, parent-directory traversal, links, unexpected executables, and duplicate entries.
- Download to a private temporary directory using unpredictable names and restrictive permissions.
- Prefer making BBDown an explicit prerequisite or require informed installation consent rather than retrieving native code automatically during
postinstall. - Document the exact upstream source, version, digests, cookie exposure, and verification procedure.
- Run the downloader with the least available privileges and, where practical, sandbox its filesystem and network access.
