com.antutu.benchmark

MEDIUM
maintainer orphaned 1 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The PKGBUILD downloads a prebuilt binary .deb from file.antutu.com (AnTuTu's own CDN/file host, not a random personal host), extracts it, and installs a proprietary benchmark binary directly into /opt/antutu with a wrapper script. The concerns are: (1) it installs an unverified prebuilt binary blob — no version pinning in the URL (no version in the filename), so the file could be silently updated server-side; (2) only an MD5 checksum is used, which is cryptographically weak and insufficient for integrity verification of an executable; (3) the binary runs with LD_LIBRARY_PATH manipulation pointing to /opt/antutu, which could be abused if the binary is compromised. While file.antutu.com appears to be AnTuTu's official distribution host, the lack of a versioned URL combined with a weak MD5 hash means there is no reliable way to verify the binary matches what was originally reviewed. This is a genuine medium-severity supply-chain concern: a prebuilt proprietary binary from a vendor CDN with weak integrity guarantees and no source build.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("http://file.antutu.com/soft/com.antutu.benchmark_amd64.deb")
Medium AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from file.antutu.com (AnTuTu's own CDN/file host, not a random personal host), extracts it, and installs a proprietary benchmark binary directly into /opt/antutu with a wrapper script. The concerns are: (1) it installs an unverified prebuilt binary blob — no version pinning in the URL (no version in the filename), so the file could be silently updated server-side; (2) only an MD5 checksum is used, which is cryptographically weak and insufficient for integrity verification of an executable; (3) the binary runs with LD_LIBRARY_PATH manipulation pointing to /opt/antutu, which could be abused if the binary is compromised. While file.antutu.com appears to be AnTuTu's official distribution host, the lack of a versioned URL combined with a weak MD5 hash means there is no reliable way to verify the binary matches what was originally reviewed. This is a genuine medium-severity supply-chain concern: a prebuilt proprietary binary from a vendor CDN with weak integrity guarantees and no source build.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zhullyb <zhullyb [at] outlook dot com>
2
3pkgname=com.antutu.benchmark
4pkgver=1.0.0.591
5pkgrel=1
6pkgdesc="安兔兔评测 for linux
7 安兔兔评测(AnTuTu)是一款跨平台,支持手机、电脑设备的专业性能评定软件。Linux版本的安兔兔支持一键跑分,可评估CPU/GPU/MEM/UX性能。"
8arch=("x86_64")
9url="https://www.antutu.com/"
10license=("custom")
11depends=()
12options=(!strip)
13provides=('antutu')
14source=("http://file.antutu.com/soft/com.antutu.benchmark_amd64.deb")
15md5sums=('f114e5fe49ad569a5ce412247a72644e')
16
17prepare(){
18 cd ${srcdir}
19 tar -xvf data.tar.zst -C "${srcdir}"
20
21}
22
23package(){
24 cd ${srcdir}
25
26 mkdir -p ${pkgdir}/opt/antutu
27 mv opt/apps/${pkgname}/files/* ${pkgdir}/opt/antutu/
28
29 mkdir -p ${pkgdir}/usr/share/
30 mv opt/apps/${pkgname}/entries/* ${pkgdir}/usr/share/
31
32 sed -i '5c Exec=antutu %U' ${pkgdir}/usr/share/applications/${pkgname}.desktop
33 echo '''#!/bin/bash
34
35export LD_LIBRARY_PATH=/opt/antutu:$LD_LIBRARY_PATH
36/opt/antutu//bin/benchmark -start $1
37''' > ${pkgdir}/opt/antutu/start.sh
38 chmod a+x ${pkgdir}/opt/antutu/start.sh
39 mkdir -p ${pkgdir}/usr/bin
40 ln -s /opt/antutu/start.sh ${pkgdir}/usr/bin/antutu
41}
42

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2
2026-09-12 00:25:17 Medium 2
2026-09-11 00:19:22 Medium 2
2026-09-10 00:22:44 Medium 2
2026-09-09 00:04:09 Medium 2
2026-09-08 00:18:08 Medium 2
2026-09-07 00:30:15 Medium 2
2026-09-06 00:17:06 Medium 2
2026-09-05 00:16:27 Medium 2
2026-09-04 00:03:13 Medium 2
2026-09-03 00:15:47 Medium 2
2026-09-02 00:02:31 Medium 2
2026-09-01 00:11:19 Medium 2
2026-08-31 00:19:57 Medium 2
2026-08-30 00:04:14 Medium 2
2026-08-29 00:29:17 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion