T03 · Remote Payload Retrieval and Execution
- Location
references/cli-plugin-installation-guide.md:28- Finding
Unverified Remote Installer Is Downloaded and Executed Directly
- Content
View full analysis
= 3.3.3 ``` ``` The bundled scripts repeat this recommendation: ```bash echo " Install: /bin/bash -c \"\$(curl -fsSL https://aliyuncli.alicdn.com/setup.sh)\"" >&2 ``` ### Technical Analysis The recommended installation procedure downloads a mutable shell script from an external URL and immediately passes its contents to Bash. There is no version pinning, cryptographic signature verification, checksum validation, local inspection step, or restriction on what the downloaded script may execute. Although the URL belongs to the declared Alibaba Cloud CLI distribution infrastructure, its content can change after this Skill has been audited. The effective code executed by the user is therefore not the code reviewed in this package. Compromise of the CDN, origin server, publishing account, DNS resolution, or certificate trust path could convert this installation command into arbitrary local code execution. This behavior is not required to provide ACK management functionality. A version-pinned and integrity-verified binary installation would satisfy the same functional requirement with substantially lower privilege and supply-chain risk. ### Attack Path 1. An attacker compromises the remote setup script, its publishing pipeline, CDN origin, or another component of its delivery path. 2. The user or Agent follows the Skill's recommended installation or upgrade instruction. 3. `curl` retrieves the attacker-controlle ...[truncated 993 chars]- Remediation
View remediation
