mc-minihud-112-liteloader

maintainer eatmyvenom · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD fetches a manifest JSON from masa.dy.fi with sha1sums='SKIP' (no integrity check), then dynamically resolves and downloads a .litemod binary URL from that manifest at build time using wget, also with no checksum verification. This is a genuine supply-chain concern: the downloaded binary's URL and filename are entirely controlled by the remote manifest, meaning a compromise of masa.dy.fi or a MITM could substitute an arbitrary binary that gets installed. The host (masa.dy.fi) appears to be the mod author Masa's personal server, which is the legitimate upstream for these Minecraft mods, so this is not clearly malicious — but the pattern of executing/installing a binary fetched from a dynamically-resolved URL with no integrity verification is a real medium-severity supply-chain risk. The 'broken' flag is not warranted as the logic appears functional. Piracy does not apply.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD fetches a manifest JSON from masa.dy.fi with sha1sums='SKIP' (no integrity check), then dynamically resolves and downloads a .litemod binary URL from that manifest at build time using wget, also with no checksum verification. This is a genuine supply-chain concern: the downloaded binary's URL and filename are entirely controlled by the remote manifest, meaning a compromise of masa.dy.fi or a MITM could substitute an arbitrary binary that gets installed. The host (masa.dy.fi) appears to be the mod author Masa's personal server, which is the legitimate upstream for these Minecraft mods, so this is not clearly malicious — but the pattern of executing/installing a binary fetched from a dynamically-resolved URL with no integrity verification is a real medium-severity supply-chain risk. The 'broken' flag is not warranted as the logic appears functional. Piracy does not apply.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
2
3_modname=minihud
4_mcver="1.12.2"
5_modloader="liteloader"
6pkgname=mc-minihud-112-liteloader
7pkgver="0.19.0.dev.20200611.151752"
8pkgrel=1
9pkgdesc="A client-side mod that allows displaying various info lines on the screen "
10arch=('any')
11url="https://masa.dy.fi/mcmods/client_mods/"
12license=('LGPL')
13makedepends=('wget' 'jq')
14source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
15sha1sums=('SKIP')
16
17pkgver() {
18 cd $srcdir
19 cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
20}
21
22build() {
23 wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"url\"]")
24}
25
26package() {
27 install -d -m 755 "${pkgdir}/usr/share/minecraft"
28
29 cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"filename\"]") \
30 "${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.litemod"
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion