mc-minihud-112-liteloader
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD fetches a manifest JSON from masa.dy.fi with sha1sums='SKIP' (no integrity check), then dynamically resolves and downloads a .litemod binary URL from that manifest at build time using wget, also with no checksum verification. This is a genuine supply-chain concern: the downloaded binary's URL and filename are entirely controlled by the remote manifest, meaning a compromise of masa.dy.fi or a MITM could substitute an arbitrary binary that gets installed. The host (masa.dy.fi) appears to be the mod author Masa's personal server, which is the legitimate upstream for these Minecraft mods, so this is not clearly malicious — but the pattern of executing/installing a binary fetched from a dynamically-resolved URL with no integrity verification is a real medium-severity supply-chain risk. The 'broken' flag is not warranted as the logic appears functional. Piracy does not apply.
PKGBUILD
1 offending line(s) highlighted# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
_modname=minihud
_mcver="1.12.2"
_modloader="liteloader"
pkgname=mc-minihud-112-liteloader
pkgver="0.19.0.dev.20200611.151752"
pkgrel=1
pkgdesc="A client-side mod that allows displaying various info lines on the screen "
arch=('any')
url="https://masa.dy.fi/mcmods/client_mods/"
license=('LGPL')
makedepends=('wget' 'jq')
source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
sha1sums=('SKIP')
pkgver() {
cd $srcdir
cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
}
build() {
wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"url\"]")
}
package() {
install -d -m 755 "${pkgdir}/usr/share/minecraft"
cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"filename\"]") \
"${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.litemod"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |