T06 · System Persistence
- Location
docs/examples.md:50- Finding
Persistent Unattended Global Software Updates Through Cron
- Content
View full analysis
> /var/log/phoenix-daily.log 2>&1 ``` ``` ### Technical Analysis The documentation recommends adding PhoenixShield to crontab so that it executes every day and performs a global npm installation. A cron entry survives the current Skill invocation and therefore establishes cross-session persistence. The task may execute as root because it uses `/usr/local/bin`, writes to `/var/log`, and performs a global npm installation. No least-privilege account, sandbox, version constraint, approval gate, or execution restrictions are specified. Persistent scheduling is not necessary for the Skill's core on-demand backup and protected-update functionality. If automated monitoring or updates are optional features, they should require explicit informed consent and use tightly constrained permissions. ### Attack Path 1. A user follows the documentation and adds the entry to a user or root crontab. 2. Cron invokes `/usr/local/bin/phoenix-shield` every day at 03:00. 3. PhoenixShield passes `npm install -g openclaw@latest` to its deployment command. 4. npm retrieves the package version currently associated with the mutable `latest` tag. 5. Package installation or lifecycle scripts execute with the privileges of the cron owner. 6. If the package, a dependency, the registry account, or the local `phoenix-shield` executable is compromised, attacker-controlled code is repeatedly executed. 7. The cron entry continues operating across sessions and system reboots until explicitly removed. ### Impact Assessment When installed in root's crontab, successful e ...[truncated 510 chars]- Remediation
View remediation
