360cloud
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:20
"http://down.360safe.com/360eyun/${pkgname}-$pkgver-deepin-${arch}.deb"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from down.360safe.com (360's official CDN/download server for their security products), extracts it, and installs the binaries directly. While down.360safe.com is 360's own distribution host (not a random personal host), the concerns are: (1) no HTTPS used for the download, making it susceptible to MITM substitution; (2) a prebuilt closed-source binary is installed without any integrity verification beyond a sha512sum of the .deb — the sha512sum does provide meaningful protection against tampering in transit; (3) 360 is a Chinese security company with a history of privacy concerns. The sha512sum does mitigate the MITM risk to some degree. However, the use of plain HTTP for a binary download is a genuine supply-chain concern even with a checksum (the checksum itself could be stale or the upstream could silently replace the binary). The binary is executed code from a closed-source vendor distributed over HTTP. This warrants medium severity — it's not clearly malicious but represents a real supply-chain risk pattern.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Jack Chen <redchenjs@live.com>
# Maintainer: taotieren <admin@taotieren.com>
pkgname=360cloud
pkgver=1.0.0.1010
pkgrel=6
pkgdesc="360 Cloud Drive / 360 安全云盘"
arch=('x86_64')
url="https://yunpan.360.cn/"
license=('custom')
backup=()
options=('!strip')
depends=(
'curl'
'libbsd'
'qt5-base'
'openssl-1.0'
)
source=(
"http://down.360safe.com/360eyun/${pkgname}-$pkgver-deepin-${arch}.deb"
)
sha512sums=(
'deafb66697250a62825b7784b1482eb69a39f61e499c3d67c8f412dc0f6c1fcc78925183ea57f307f7c176cc9a67838fcbe00d81833e6a7e23a0574e95452a1d'
)
package() {
tar -xf "${srcdir}/data.tar.xz" -C "${pkgdir}/"
ln -sf "/opt/${pkgname}/${pkgname}" "${pkgdir}/usr/bin/${pkgname}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |