az
Audited by Socket on Sep 6, 2026
2 alerts found:
Anomalyx2This is likely a legitimate Azure CLI installer, but it carries a meaningful supply-chain integrity risk on Debian/Ubuntu: it downloads an external script from a redirect endpoint and executes it as root without any explicit checksum/signature validation or safer temp handling. No direct evidence of malware behavior (exfiltration/backdoor/credential theft) is present in the provided code, but the unverified remote code execution step warrants security review and hardening (e.g., pinned versions and cryptographic verification).
No direct malware behaviors are evident in the provided script. The dominant security concern is the Debian/Ubuntu install path that downloads and executes a remote script as root via curl -sL ... | sudo bash without integrity verification/pinning in this snippet. Everything else is straightforward OS detection, package installation via standard managers, and post-install verification with az --version.