evostream-libavbin

maintainer tomi77 · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt binary .deb from apt.evostream.com (the vendor's own Debian APT repository) and installs its contents directly. While apt.evostream.com appears to be EvoStream's official distribution host (consistent with their product ecosystem), it is not a major distro mirror or well-known CDN, and the binary is executed/installed without any signature verification beyond an MD5 checksum (which is weak). The concern is real but not clearly malicious: if the host were compromised or the binary swapped, the MD5 would not protect against a targeted attack. This is a classic medium-severity supply-chain pattern — prebuilt binary from a vendor-controlled but non-mainstream host with only weak integrity checking. No obfuscation, no piracy, and the package appears functional.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("http://apt.evostream.com/release/debian/9.4/pool/main/e/evostream-libavbin/${pkgname}_${pkgver}-1_amd64.deb"
  • PKGBUILD:13 "https://evostream.com/public/files/Evostream-Media-Server-EULA-v2.pdf")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary .deb from apt.evostream.com (the vendor's own Debian APT repository) and installs its contents directly. While apt.evostream.com appears to be EvoStream's official distribution host (consistent with their product ecosystem), it is not a major distro mirror or well-known CDN, and the binary is executed/installed without any signature verification beyond an MD5 checksum (which is weak). The concern is real but not clearly malicious: if the host were compromised or the binary swapped, the MD5 would not protect against a targeted attack. This is a classic medium-severity supply-chain pattern — prebuilt binary from a vendor-controlled but non-mainstream host with only weak integrity checking. No obfuscation, no piracy, and the package appears functional.

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: Tomasz Jakub Rup <tomasz.rup@gmail.com>
2pkgname=evostream-libavbin
3pkgver=2.0.1.5649
4pkgrel=3
5pkgdesc="libav project compiled by EvoStream"
6arch=('x86_64' 'i686')
7url="https://evostream.com/"
8license=('custom')
9makedepends=('poppler')
10provides=('evostreamms-libavbin')
11conflicts=('evostreamms-libavbin')
12source=("http://apt.evostream.com/release/debian/9.4/pool/main/e/evostream-libavbin/${pkgname}_${pkgver}-1_amd64.deb"
13 "https://evostream.com/public/files/Evostream-Media-Server-EULA-v2.pdf")
14md5sums=('69d27f2a7265550598668ac64e995de8'
15 'ee93910c6589b26c8eb056921f1944f8')
16noextract=("Evostream-Media-Server-EULA-v2.pdf")
17
18build() {
19 msg2 "Preparing license..."
20 pdftotext ${srcdir}/Evostream-Media-Server-EULA-v2.pdf
21}
22
23package() {
24 depends=('zlib' 'bash')
25
26 msg2 "Extracting the data.tar.xz..."
27 bsdtar -xf data.tar.xz -C "${pkgdir}/"
28
29 msg2 "Adding license..."
30 install -Dm644 "${srcdir}/Evostream-Media-Server-EULA-v2.txt" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion