T03 · Remote Payload Retrieval and Execution
- Location
scripts/bootstrap.sh:46- Finding
Remote NodeSource installer is executed directly with root privileges
- Content
View full analysis
/dev/null sudo apt-get install -y -qq nodejs 2>/dev/null log "Node.js $(node --version) installed" fi ``` ### Technical Analysis The script downloads mutable shell code from an external URL and immediately pipes it into `sudo bash`. The downloaded content is not pinned to a cryptographic digest, verified using a trusted signature, or saved for inspection before execution. HTTPS protects the connection in ordinary circumstances, but it does not protect against compromise of NodeSource infrastructure, unauthorized modification of the hosted installer, certificate or trust-store compromise, or an upstream account takeover. Because `sudo -E bash` runs the response as root while preserving environment variables, any command introduced into the response receives complete control of the VPS. This behavior exceeds the privileges needed merely to retrieve repository metadata: the effective root-level payload can change after the Skill has been audited. ### Attack Path 1. An attacker compromises the remote installer, its hosting infrastructure, or the delivery path. 2. The administrator invokes `scripts/bootstrap.sh`. 3. `curl` retrieves the attacker-modified response. 4. The response is passed directly to `sudo -E bash`. 5. Attacker-controlled commands execute as root and may modify system files, create accounts, install services, access local data, or deploy additional payloads. ### Impact Assessment Successful exploitation provides arbitrary root-level code execution over the entire VPS. The attacker can access all users' files, credentials, OpenClaw state, and network-accessible resources; disable security control ...[truncated 48 chars]- Remediation
View remediation
