I set up a quick demonstration to show risks of curl|bash and how a bad-actor could potentially hide a malicious script.

It’s nothing new or groundbreaking, but I figure it never hurts to have another reminder.

  • Wildmimic@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    8 hours ago

    In addition to the other examples it’s also in the default installation mode for node.js - they use this to install nvm

    Ya cant even blame someone non-technical falling for this if they haven’t been explicitly informed - it’s getting reinforced as completely normal by too many “reputable” projects.