mc-itemscroller-112-liteloader

maintainer eatmyvenom · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD fetches a manifest JSON from masa.dy.fi with SKIP checksum, then dynamically resolves and downloads a mod binary (.litemod) URL from that manifest at build time. The actual binary URL and filename are entirely controlled by the remote manifest — there is no integrity verification (no checksum) on either the manifest or the downloaded binary. This is a genuine supply-chain concern: if masa.dy.fi is compromised or the API response is tampered with (e.g. via MITM), an arbitrary binary would be installed. However, masa.dy.fi is the known personal site of the mod author 'masa' (Matti Ruohonen), a well-known Minecraft modder, so this is not a random untrusted host — it is the upstream vendor's own distribution channel. The pattern of fetching a dynamic manifest to get the latest URL is unusual but not inherently malicious. The lack of any checksum verification on the downloaded binary is the real concern, keeping this at medium rather than clean.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 85%): The PKGBUILD fetches a manifest JSON from masa.dy.fi with SKIP checksum, then dynamically resolves and downloads a mod binary (.litemod) URL from that manifest at build time. The actual binary URL and filename are entirely controlled by the remote manifest — there is no integrity verification (no checksum) on either the manifest or the downloaded binary. This is a genuine supply-chain concern: if masa.dy.fi is compromised or the API response is tampered with (e.g. via MITM), an arbitrary binary would be installed. However, masa.dy.fi is the known personal site of the mod author 'masa' (Matti Ruohonen), a well-known Minecraft modder, so this is not a random untrusted host — it is the upstream vendor's own distribution channel. The pattern of fetching a dynamic manifest to get the latest URL is unusual but not inherently malicious. The lack of any checksum verification on the downloaded binary is the real concern, keeping this at medium rather than clean.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
2
3_modname=itemscroller
4_mcver="1.12.2"
5_modloader="liteloader"
6pkgname=mc-itemscroller-112-liteloader
7pkgver="0.15.0.dev.20200427.013720"
8pkgrel=1
9pkgdesc="Library mod containing shared code for masas client-side mods."
10arch=('any')
11url="https://masa.dy.fi/mcmods/client_mods/"
12license=('LGPL')
13makedepends=('wget' 'jq')
14source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
15sha1sums=('SKIP')
16
17pkgver() {
18 cd $srcdir
19 cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
20}
21
22build() {
23 wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"url\"]")
24}
25
26package() {
27 install -d -m 755 "${pkgdir}/usr/share/minecraft"
28
29 cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"filename\"]") \
30 "${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.litemod"
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion