com.antutu.benchmark

maintainer orphaned · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from file.antutu.com (AnTuTu's own CDN/file host, not a random personal host), extracts it, and installs a proprietary benchmark binary directly into /opt/antutu with a wrapper script. The concerns are: (1) it installs an unverified prebuilt binary blob — no version pinning in the URL (no version in the filename), so the file could be silently updated server-side; (2) only an MD5 checksum is used, which is cryptographically weak and insufficient for integrity verification of an executable; (3) the binary runs with LD_LIBRARY_PATH manipulation pointing to /opt/antutu, which could be abused if the binary is compromised. While file.antutu.com appears to be AnTuTu's official distribution host, the lack of a versioned URL combined with a weak MD5 hash means there is no reliable way to verify the binary matches what was originally reviewed. This is a genuine medium-severity supply-chain concern: a prebuilt proprietary binary from a vendor CDN with weak integrity guarantees and no source build.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("http://file.antutu.com/soft/com.antutu.benchmark_amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from file.antutu.com (AnTuTu's own CDN/file host, not a random personal host), extracts it, and installs a proprietary benchmark binary directly into /opt/antutu with a wrapper script. The concerns are: (1) it installs an unverified prebuilt binary blob — no version pinning in the URL (no version in the filename), so the file could be silently updated server-side; (2) only an MD5 checksum is used, which is cryptographically weak and insufficient for integrity verification of an executable; (3) the binary runs with LD_LIBRARY_PATH manipulation pointing to /opt/antutu, which could be abused if the binary is compromised. While file.antutu.com appears to be AnTuTu's official distribution host, the lack of a versioned URL combined with a weak MD5 hash means there is no reliable way to verify the binary matches what was originally reviewed. This is a genuine medium-severity supply-chain concern: a prebuilt proprietary binary from a vendor CDN with weak integrity guarantees and no source build.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zhullyb <zhullyb [at] outlook dot com>
2
3pkgname=com.antutu.benchmark
4pkgver=1.0.0.591
5pkgrel=1
6pkgdesc="安兔兔评测 for linux
7 安兔兔评测(AnTuTu)是一款跨平台,支持手机、电脑设备的专业性能评定软件。Linux版本的安兔兔支持一键跑分,可评估CPU/GPU/MEM/UX性能。"
8arch=("x86_64")
9url="https://www.antutu.com/"
10license=("custom")
11depends=()
12options=(!strip)
13provides=('antutu')
14source=("http://file.antutu.com/soft/com.antutu.benchmark_amd64.deb")
15md5sums=('f114e5fe49ad569a5ce412247a72644e')
16
17prepare(){
18 cd ${srcdir}
19 tar -xvf data.tar.zst -C "${srcdir}"
20
21}
22
23package(){
24 cd ${srcdir}
25
26 mkdir -p ${pkgdir}/opt/antutu
27 mv opt/apps/${pkgname}/files/* ${pkgdir}/opt/antutu/
28
29 mkdir -p ${pkgdir}/usr/share/
30 mv opt/apps/${pkgname}/entries/* ${pkgdir}/usr/share/
31
32 sed -i '5c Exec=antutu %U' ${pkgdir}/usr/share/applications/${pkgname}.desktop
33 echo '''#!/bin/bash
34
35export LD_LIBRARY_PATH=/opt/antutu:$LD_LIBRARY_PATH
36/opt/antutu//bin/benchmark -start $1
37''' > ${pkgdir}/opt/antutu/start.sh
38 chmod a+x ${pkgdir}/opt/antutu/start.sh
39 mkdir -p ${pkgdir}/usr/bin
40 ln -s /opt/antutu/start.sh ${pkgdir}/usr/bin/antutu
41}
42

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion