T03 · Remote Payload Retrieval and Execution
- Location
scripts/silent-update.sh:47- Finding
Unverified Remote Application Retrieval and Installation
- Content
View full analysis
&1 | tee -a "$LOG_FILE" log "安装App..." # 卸载旧版 rm -rf /Applications/OpenClaw.app 2>/dev/null || true # 挂载dmg并安装 hdiutil attach "$DMG_PATH" -nobrowse 2>&1 | tee -a "$LOG_FILE" cp -R "/Volumes/OpenClaw/OpenClaw.app" /Applications/ 2>&1 | tee -a "$LOG_FILE" hdiutil detach "/Volumes/OpenClaw" 2>&1 | tee -a "$LOG_FILE" rm -f "$DMG_PATH" log "App更新完成" ``` ### Technical Analysis The script retrieves a mutable application artifact from the latest GitHub release and installs it without verifying a cryptographic checksum, signed release manifest, macOS code-signing identity, or Gatekeeper assessment. HTTPS protects the connection in transit but does not establish that the release itself is trustworthy if the upstream repository, release account, or publishing workflow is compromised. Because the effective application payload can change after the Skill has been reviewed, the downloaded artifact is outside the audited package. The `curl` invocation uses `-L` but not `--fail`. Consequently, HTTP error responses may be written to the expected DMG path before the existing application is removed. The script deletes `/Applications/OpenClaw.app` before confirming that the downloaded image is valid and contains an authentic application, creating an additional denial-of-service and rollback risk. ### Attack Path 1. An attacker compromises the upstream GitHub repository, maintainer account, release workflow, or release artifact. 2. The attacker publishes a release that matches the expected ...[truncated 1258 chars]- Remediation
View remediation
