mc-malilib-117-fabric

maintainer eatmyvenom · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a JSON manifest from masa.dy.fi (a personal/unofficial host run by the mod author 'masa') and then dynamically resolves and downloads a JAR file URL from that manifest at build time using wget. The actual JAR binary is not listed in source=() and has no checksum verification — only the manifest JSON has a sha1sum. This means the executed JAR (a Minecraft mod) is fetched from an unverified URL extracted at runtime from the manifest, with no integrity check. While masa.dy.fi appears to be the legitimate personal site of the well-known Minecraft modder 'masa' (author of malilib, litematica, etc.), the pattern of fetching an unsigned binary from a personal host without a checksum is a genuine supply-chain concern: if the host is compromised or the manifest is tampered with, an arbitrary JAR would be installed without detection. This is a real medium-severity supply-chain risk, not a false positive.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a JSON manifest from masa.dy.fi (a personal/unofficial host run by the mod author 'masa') and then dynamically resolves and downloads a JAR file URL from that manifest at build time using wget. The actual JAR binary is not listed in source=() and has no checksum verification — only the manifest JSON has a sha1sum. This means the executed JAR (a Minecraft mod) is fetched from an unverified URL extracted at runtime from the manifest, with no integrity check. While masa.dy.fi appears to be the legitimate personal site of the well-known Minecraft modder 'masa' (author of malilib, litematica, etc.), the pattern of fetching an unsigned binary from a personal host without a checksum is a genuine supply-chain concern: if the host is compromised or the manifest is tampered with, an arbitrary JAR would be installed without detection. This is a real medium-severity supply-chain risk, not a false positive.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
2
3_modname=malilib
4_mcver="1.17-snapshot-21w05a"
5_modloader="fabric"
6pkgname=mc-malilib-117-fabric
7pkgver="0.10.0.dev.21.beta.1"
8pkgrel=1
9pkgdesc="Library mod containing shared code for masas client-side mods."
10arch=('any')
11url="https://masa.dy.fi/mcmods/client_mods/"
12license=('LGPL')
13makedepends=('wget' 'jq')
14source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
15sha1sums=('3b3c19c94ad38288f78222b4c72847f44df81b34')
16
17pkgver() {
18 cd $srcdir
19 cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
20}
21
22build() {
23 wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"url\"]")
24}
25
26package() {
27 install -d -m 755 "${pkgdir}/usr/share/minecraft"
28
29 cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"filename\"]") \
30 "${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.jar"
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion