External Script Fetching
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The document instructs users to download and immediately execute a remote shell script via
curl ... | bash, which bypasses any opportunity to inspect, pin, or verify the installer before execution. If the hosting bucket, CDN path, TLS trust chain, or upstream release process were compromised, this would result in arbitrary code execution on the user's machine with the user's privileges.- Content
After installation authorization, use the Bash installer on macOS/Linux:
bash curl --proto '=https' --proto-redir '=https' -fsSL https://aliyun-dts-cli.oss-cn-hangzhou.aliyuncs.com/install.sh | bash -s -- --yesUse
--yesonly for a non-interactive installation the user has already authorized. Do not run the installer before that authorization exists.
