T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:76- Finding
Mutable Remote Repository Is Retrieved and Executed Without Integrity Verification
- Content
View full analysis
/dev/null || warn "Could not pull (may have local changes)" fi else log "Cloning dashboard to $INSTALL_DIR..." mkdir -p "$(dirname "$INSTALL_DIR")" git clone "$REPO_URL" "$INSTALL_DIR" fi cd "$INSTALL_DIR" # --- Install dependencies --- log "Installing dependencies..." npm install ``` ```bash # --- Build --- log "Building project..." npm run build # --- Start --- if [[ $HAS_PM2 -eq 1 ]]; then log "Starting with PM2..." # Stop existing instances if running pm2 delete corkie-server 2>/dev/null || true pm2 delete corkie-client 2>/dev/null || true npm run pm2:start ``` ### Technical Analysis The installer clones or updates a mutable Git repository and immediately executes repository-controlled npm lifecycle, build, and PM2 scripts. It does not pin a reviewed commit or signed release and does not verify a cryptographic checksum, Git signature, or expected revision. `git pull --ff-only` prevents non-fast-forward history changes but does not establish trust in newly fetched commits. Likewise, `npm install` can execute lifecycle hooks from the project and its dependencies. The subsequent `npm run build` and `npm run pm2:start` commands execute scripts defined by the remotely retrieved project. Although remote installation is part of the declared setup behavior, the absence of integrity controls means the code executed at installation time can differ from the code reviewed in this Skill package. ### Attack Path 1. An attacker compromises the upstream repository, a maintainer account, or a dependency referenced ...[truncated 1052 chars]- Remediation
View remediation
