dextra

maintainer kleintux · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary tarball from newandroidbook.com, a personal/unofficial site run by the tool's author (Jonathan Levin), and installs one of the contained ELF binaries directly to /usr/bin without any build step. While newandroidbook.com is a well-known Android internals research site and the author is a recognized security researcher, the host is still a personal domain rather than an official forge or distribution channel. The sha256sum provides integrity checking against accidental corruption but offers no protection if the upstream host is compromised or the binary is silently replaced. Installing an unverified prebuilt binary from a personal host is a genuine supply-chain concern: there is no source code to audit, no reproducible build, and no GPG signature verification. This fits the medium category — not clearly malicious, but a real code-execution risk from an unofficial binary host.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=("http://newandroidbook.com/files/${pkgname}.tar")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt binary tarball from newandroidbook.com, a personal/unofficial site run by the tool's author (Jonathan Levin), and installs one of the contained ELF binaries directly to /usr/bin without any build step. While newandroidbook.com is a well-known Android internals research site and the author is a recognized security researcher, the host is still a personal domain rather than an official forge or distribution channel. The sha256sum provides integrity checking against accidental corruption but offers no protection if the upstream host is compromised or the binary is silently replaced. Installing an unverified prebuilt binary from a personal host is a genuine supply-chain concern: there is no source code to audit, no reproducible build, and no GPG signature verification. This fits the medium category — not clearly malicious, but a real code-execution risk from an unofficial binary host.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Gavin Lloyd <gavinhungry@gmail.com>
2
3pkgname=dextra
4pkgver=1.38.114
5pkgrel=2
6pkgdesc='A tool for DEX and OAT dumping, decompilation, and fuzzing'
7arch=('i686' 'x86_64' 'armv7h')
8url='http://newandroidbook.com/tools/dextra.html'
9license=('unknown')
10source=("http://newandroidbook.com/files/${pkgname}.tar")
11sha256sums=('7e4bfc90a50d2e96a5d1bd06557e35194204b3f85a9bbaade2b2942d088ea1ea')
12
13package() {
14 case "${CARCH}" in
15 i686) install -Dm755 "${srcdir}"/dextra "${pkgdir}"/usr/bin/dextra ;;
16 x86_64) install -Dm755 "${srcdir}"/dextra.ELF64 "${pkgdir}"/usr/bin/dextra ;;
17 armv7h) install -Dm755 "${srcdir}"/dextra.armv7 "${pkgdir}"/usr/bin/dextra ;;
18 esac
19}
20

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion