mc-malilib-116-fabric

maintainer eatmyvenom · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD fetches a manifest JSON from masa.dy.fi with 'SKIP' checksum, then dynamically resolves and downloads a JAR file URL from that manifest at build time using wget — also with no integrity verification. This is a two-stage supply-chain risk: (1) the manifest itself has no checksum, so its contents can change arbitrarily, and (2) the JAR URL and filename are entirely controlled by whatever the manifest returns at build time, meaning a compromise of masa.dy.fi could serve a malicious JAR that gets installed as a Minecraft mod. The host masa.dy.fi is Masa's personal/unofficial distribution site, not an official Maven/Modrinth/CurseForge mirror. The executed artifact (a JAR loaded by Minecraft's classloader) is effectively arbitrary code execution in the user's game context. This is a genuine supply-chain concern: no pinned version in the source URL, no checksum on the downloaded JAR, and the actual download happens inside build() via wget rather than through makepkg's verified source mechanism. The cheaper model's MEDIUM rating is correct.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 85%): The PKGBUILD fetches a manifest JSON from masa.dy.fi with 'SKIP' checksum, then dynamically resolves and downloads a JAR file URL from that manifest at build time using wget — also with no integrity verification. This is a two-stage supply-chain risk: (1) the manifest itself has no checksum, so its contents can change arbitrarily, and (2) the JAR URL and filename are entirely controlled by whatever the manifest returns at build time, meaning a compromise of masa.dy.fi could serve a malicious JAR that gets installed as a Minecraft mod. The host masa.dy.fi is Masa's personal/unofficial distribution site, not an official Maven/Modrinth/CurseForge mirror. The executed artifact (a JAR loaded by Minecraft's classloader) is effectively arbitrary code execution in the user's game context. This is a genuine supply-chain concern: no pinned version in the source URL, no checksum on the downloaded JAR, and the actual download happens inside build() via wget rather than through makepkg's verified source mechanism. The cheaper model's MEDIUM rating is correct.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
2
3_modname=malilib
4_mcver="1.16.4"
5pkgname=mc-malilib-116-fabric
6pkgver="0.10.0.dev.21.arne.2"
7pkgrel=1
8pkgdesc="Library mod containing shared code for masas client-side mods."
9arch=('any')
10url="https://masa.dy.fi/mcmods/client_mods/"
11license=('LGPL')
12makedepends=('wget' 'jq')
13source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
14sha1sums=('SKIP')
15
16pkgver() {
17 cd $srcdir
18 cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
19}
20
21build() {
22 wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"url\"]")
23}
24
25package() {
26 install -d -m 755 "${pkgdir}/usr/share/minecraft"
27
28 cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"filename\"]") \
29 "${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.jar"
30}
31

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion