External Script Fetching
- Category
- Supply Chain
- Confidence
- 99% confidence
- Finding
This is a classic external script fetching pattern: 'curl' retrieves a remote installer and 'bash' executes it locally. That creates a direct code execution path from a mutable remote resource to the user's machine, making compromise of the download source or script content immediately dangerous.
- Content
Linux and MacOS System Installation
bash curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.shThe above command downloads KooCLI to "/usr/local/hcloud/" directory by default and moves it to "/usr/local/bin/" directory for convenient use of hcloud command in any directory (before completing this step, please ensure PATH system variable contains "/usr/local/bin/" path).
