T08 · Insecure Dependencies
- Location
scripts/setup_biliup.sh:33- Finding
Unpinned Installation of the biliup Package
- Content
View full analysis
/dev/null; then echo "🛠️ 使用 pipx 安装..." pipx install biliup echo "✅ biliup 安装成功(pipx)" exit 0 fi # 回退到 pip install --user if command -v pip3 &>/dev/null; then echo "🛠️ 使用 pip3 install --user 安装..." pip3 install --user biliup elif command -v pip &>/dev/null; then echo "🛠️ 使用 pip install --user 安装..." pip install --user biliup else ``` ### Technical Analysis The setup script installs `biliup` by package name without pinning a reviewed version or verifying package hashes. Each invocation can therefore resolve to a different package release and transitive dependency set. Installation of a Python package can execute package-controlled build and installation logic. Although `biliup` is a plausible package from the expected package index and no direct evidence of a currently malicious release was found, the installation process trusts mutable upstream artifacts without integrity constraints. The resulting CLI is subsequently used with Bilibili authentication credentials and user video files. Using `pipx` provides environment isolation but does not address package authenticity, release mutability, or integrity verification. ### Attack Path 1. An attacker compromises the upstream `biliup` package, one of its dependencies, or the package distribution account. 2. A malicious or compromised release becomes the version resolved by `pipx` or `pip`. 3. A user runs `scripts/setup_biliup.sh`. 4. The package manager downloads and installs the mutable release without checking a pinned version or expected hash. 5. Malicious installation logic or imported runtime code executes with the privileges of the user running the script. 6. The malicious package can access files available to that u ...[truncated 445 chars]- Remediation
View remediation
