T03 · Remote Payload Retrieval and Execution
- Location
install.sh:9- Finding
Privileged Execution of a Mutable Remote NodeSource Script
- Content
View full analysis
/dev/null then echo "Node.js not found. Installing Node.js..." curl -fsSL https://deb.nodesource.com/setup_14.x | sudo -E bash - sudo apt-get install -y nodejs ``` ### Technical Analysis The installer downloads a mutable script from an external URL and pipes it directly into a root shell. The downloaded content is not pinned to a cryptographic digest, verified using a publisher signature, saved for review, or otherwise authenticated beyond HTTPS. Because the effective script can change after the Skill has been reviewed, this creates a remote code-execution channel. The behavior also exceeds minimum privilege requirements: installing Node.js may legitimately require package-manager privileges, but executing an arbitrary remote response as root is not necessary. ### Attack Path 1. A user runs `bash install.sh` on a system where Node.js is absent. 2. The installer requests the NodeSource setup script. 3. An attacker compromises the remote hosting account, delivery infrastructure, DNS/TLS trust chain, or upstream script. 4. The attacker returns a modified shell script. 5. `sudo -E bash -` executes the response immediately with root privileges. 6. The payload can modify the operating system, access local data, install persistence, or replace trusted executables. ### Impact Assessment Successful exploitation provides arbitrary root-level command execution and can result in complete host compromise. The attacker could read or alter wallet files, steal RPC credentials, replace system binaries, install persistent services, or manipulate future blockchain transactions. ]]>- Remediation
View remediation
