cupp-v3

maintainer robertfoster · 6 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a tarball from the project's official site (remote-exploit.org), which is not on the whitelist but is plausibly the legitimate upstream; the package builds from source and installs only data and a small wrapper script, with no obfuscated or executable payloads.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the project's official site (remote-exploit.org), which is not on the whitelist but is plausibly the legitimate upstream; the package builds from source and installs only data and a small wrapper script, with no obfuscated or executable payloads.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=(http://www.remote-exploit.org/content/cupp-$pkgver.tar.gz

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: robertfoster
2
3pkgname=cupp-v3
4pkgver=3.0
5pkgrel=1
6pkgdesc="Common User Passwords Profiler "
7arch=('i686' 'x86_64')
8url="http://www.remote-exploit.org/?page_id=418"
9depends=('python2')
10license=('GPL')
11source=(http://www.remote-exploit.org/content/cupp-$pkgver.tar.gz
12 cupp-bin)
13
14package() {
15 # Organize the paths
16 mkdir -p $pkgdir/usr/share/
17 cp -r $srcdir/cupp $pkgdir/usr/share/
18
19 # Create the executable link
20 mkdir -p $pkgdir/usr/bin
21 cp $srcdir/cupp-bin $pkgdir/usr/bin/cupp
22
23}
24
25sha256sums=('d85f862c7255c27a4cdca1943d175356db54ebaa87d0d88f5d20d447d3710ee8'
26 'cb5f7f14e89a97306af59152a6d5a6afa88e5c0aeb671f4e8613c6a0699ac7a2')
27

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion