evostream-libavbin
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("http://apt.evostream.com/release/debian/9.4/pool/main/e/evostream-libavbin/${pkgname}_${pkgver}-1_amd64.deb" -
PKGBUILD:13
"https://evostream.com/public/files/Evostream-Media-Server-EULA-v2.pdf")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from apt.evostream.com (the vendor's own Debian APT repository) and installs its contents directly. While apt.evostream.com appears to be EvoStream's official distribution host (consistent with their product ecosystem), it is not a major distro mirror or well-known CDN, and the binary is executed/installed without any signature verification beyond an MD5 checksum (which is weak). The concern is real but not clearly malicious: if the host were compromised or the binary swapped, the MD5 would not protect against a targeted attack. This is a classic medium-severity supply-chain pattern — prebuilt binary from a vendor-controlled but non-mainstream host with only weak integrity checking. No obfuscation, no piracy, and the package appears functional.
PKGBUILD
2 offending line(s) highlighted# Maintainer: Tomasz Jakub Rup <tomasz.rup@gmail.com>
pkgname=evostream-libavbin
pkgver=2.0.1.5649
pkgrel=3
pkgdesc="libav project compiled by EvoStream"
arch=('x86_64' 'i686')
url="https://evostream.com/"
license=('custom')
makedepends=('poppler')
provides=('evostreamms-libavbin')
conflicts=('evostreamms-libavbin')
source=("http://apt.evostream.com/release/debian/9.4/pool/main/e/evostream-libavbin/${pkgname}_${pkgver}-1_amd64.deb"
"https://evostream.com/public/files/Evostream-Media-Server-EULA-v2.pdf")
md5sums=('69d27f2a7265550598668ac64e995de8'
'ee93910c6589b26c8eb056921f1944f8')
noextract=("Evostream-Media-Server-EULA-v2.pdf")
build() {
msg2 "Preparing license..."
pdftotext ${srcdir}/Evostream-Media-Server-EULA-v2.pdf
}
package() {
depends=('zlib' 'bash')
msg2 "Extracting the data.tar.xz..."
bsdtar -xf data.tar.xz -C "${pkgdir}/"
msg2 "Adding license..."
install -Dm644 "${srcdir}/Evostream-Media-Server-EULA-v2.txt" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |