quarkclouddrive

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
install.sh

This module is a high-impact supply-chain installer. It retrieves a remote config to determine a remote ZIP URL, downloads and unzips the package without shown integrity/signature verification, copies the extracted scripts into the installation directory, and then executes the installed Node entry script for verification. On Linux, it also bootstraps Node using privileged `curl | sudo bash` execution. While there is no explicit stealth/exfiltration logic visible in this Bash file, the permissive trust and download-and-execute pipeline make the overall package execution trust highly sensitive to upstream compromise, malicious package delivery, or tampering of remote responses.

Confidence: 66%Severity: 85%
Audit Metadata
Analyzed At
Sep 7, 2026, 04:11 AM
Package URL
pkg:socket/skills-sh/quark-clouddrive%2Fquarkclouddrive_offical%2Fquarkclouddrive%2F@1cb2cc4ef93940851e4671a4ce6d696411ef1365c891cbb80c285fd9c1e6fa5b
Security Audit — socket — quarkclouddrive