External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The command downloads a shell script from the network and immediately executes it with bash, creating a classic remote-code-execution and supply-chain risk if the hosting location, transport, or artifact is compromised. In the context of a cloud administration skill, users may run this on systems that also hold cloud credentials, amplifying the potential damage.
- Content
One-click Installation
bash # Download and run official installation script (interactive) curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh # Non-interactive installation (skip confirmation) curl -sSL https://cn-north-4-hdn-koocli.obs.cn-north-4.myhuaweicloud.com/cli/latest/hcloud_install.sh -o ./hcloud_install.sh && bash ./hcloud_install.sh -y
