com.antutu.benchmark
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("http://file.antutu.com/soft/com.antutu.benchmark_amd64.deb")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from file.antutu.com (AnTuTu's own CDN/file host, not a random personal host), extracts it, and installs a proprietary benchmark binary directly into /opt/antutu with a wrapper script. The concerns are: (1) it installs an unverified prebuilt binary blob — no version pinning in the URL (no version in the filename), so the file could be silently updated server-side; (2) only an MD5 checksum is used, which is cryptographically weak and insufficient for integrity verification of an executable; (3) the binary runs with LD_LIBRARY_PATH manipulation pointing to /opt/antutu, which could be abused if the binary is compromised. While file.antutu.com appears to be AnTuTu's official distribution host, the lack of a versioned URL combined with a weak MD5 hash means there is no reliable way to verify the binary matches what was originally reviewed. This is a genuine medium-severity supply-chain concern: a prebuilt proprietary binary from a vendor CDN with weak integrity guarantees and no source build.
PKGBUILD
1 offending line(s) highlighted# Maintainer: zhullyb <zhullyb [at] outlook dot com>
pkgname=com.antutu.benchmark
pkgver=1.0.0.591
pkgrel=1
pkgdesc="安兔兔评测 for linux
安兔兔评测(AnTuTu)是一款跨平台,支持手机、电脑设备的专业性能评定软件。Linux版本的安兔兔支持一键跑分,可评估CPU/GPU/MEM/UX性能。"
arch=("x86_64")
url="https://www.antutu.com/"
license=("custom")
depends=()
options=(!strip)
provides=('antutu')
source=("http://file.antutu.com/soft/com.antutu.benchmark_amd64.deb")
md5sums=('f114e5fe49ad569a5ce412247a72644e')
prepare(){
cd ${srcdir}
tar -xvf data.tar.zst -C "${srcdir}"
}
package(){
cd ${srcdir}
mkdir -p ${pkgdir}/opt/antutu
mv opt/apps/${pkgname}/files/* ${pkgdir}/opt/antutu/
mkdir -p ${pkgdir}/usr/share/
mv opt/apps/${pkgname}/entries/* ${pkgdir}/usr/share/
sed -i '5c Exec=antutu %U' ${pkgdir}/usr/share/applications/${pkgname}.desktop
echo '''#!/bin/bash
export LD_LIBRARY_PATH=/opt/antutu:$LD_LIBRARY_PATH
/opt/antutu//bin/benchmark -start $1
''' > ${pkgdir}/opt/antutu/start.sh
chmod a+x ${pkgdir}/opt/antutu/start.sh
mkdir -p ${pkgdir}/usr/bin
ln -s /opt/antutu/start.sh ${pkgdir}/usr/bin/antutu
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |