T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:27- Finding
Privileged installation of remotely retrieved packages from mutable third-party mirrors
- Content
View full analysis
/dev/null && [ -s "/tmp/$MACFUSE_DMG" ]; then dmg="/tmp/$MACFUSE_DMG" break fi done xattr -d com.apple.quarantine "$dmg" 2>/dev/null || true mnt=$(hdiutil attach "$dmg" -nobrowse -noautoopen 2>/dev/null | awk -F'\t' '/Volumes/{print $NF}') pkg=$(find "$mnt" -maxdepth 2 -name '*.pkg' 2>/dev/null | head -1) if command -v pkgutil >/dev/null 2>&1 && pkgutil --check-signature "$pkg" >/dev/null 2>&1; then echo " Package signature validation passed" else hdiutil detach "$mnt" >/dev/null 2>&1 || true exit 1 fi sudo installer -pkg "$pkg" -target / >/dev/null 2>&1 hdiutil detach "$mnt" >/dev/null 2>&1 || true ``` ### Technical Analysis The installer downloads a macFUSE disk image through multiple mutable, third-party GitHub proxy services and subsequently installs a package from that image with root privileges. The script does not verify a pinned cryptographic digest for the DMG or package. Its `pkgutil --check-signature` call only checks whether macOS recognizes a package signature; it does not explicitly compare the signer identity or Team ID against a hardcoded expected macFUSE publisher. The script also follows r ...[truncated 1553 chars]- Remediation
View remediation
