mc-minihud-116-fabric

maintainer eatmyvenom · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads a JAR file (executed JVM bytecode/compiled code) from masa.dy.fi, which is a personal/unofficial host run by the mod author (Matti Ruohonen, known as 'masa' in the Minecraft modding community). Two concrete supply-chain concerns exist: (1) The manifest.json is fetched with sha1sums='SKIP', meaning no integrity check is performed on the file that determines what gets downloaded and installed. (2) The actual JAR URL is resolved dynamically at build time from that unverified manifest, so a compromise of masa.dy.fi or a MITM could redirect the download to an arbitrary JAR. The JAR itself is installed to /usr/share/minecraft and executed by users' Minecraft clients. While masa.dy.fi is a well-known personal host for this specific modder and not obviously malicious, it is not an official distribution channel (e.g., CurseForge, Modrinth), and the complete absence of any checksum verification for both the manifest and the resulting JAR constitutes a genuine supply-chain risk for executed code. This correctly rates as MEDIUM.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 85%): This PKGBUILD downloads a JAR file (executed JVM bytecode/compiled code) from masa.dy.fi, which is a personal/unofficial host run by the mod author (Matti Ruohonen, known as 'masa' in the Minecraft modding community). Two concrete supply-chain concerns exist: (1) The manifest.json is fetched with sha1sums='SKIP', meaning no integrity check is performed on the file that determines what gets downloaded and installed. (2) The actual JAR URL is resolved dynamically at build time from that unverified manifest, so a compromise of masa.dy.fi or a MITM could redirect the download to an arbitrary JAR. The JAR itself is installed to /usr/share/minecraft and executed by users' Minecraft clients. While masa.dy.fi is a well-known personal host for this specific modder and not obviously malicious, it is not an official distribution channel (e.g., CurseForge, Modrinth), and the complete absence of any checksum verification for both the manifest and the resulting JAR constitutes a genuine supply-chain risk for executed code. This correctly rates as MEDIUM.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
2
3_modname=minihud
4_mcver="1.16.4"
5pkgname=mc-minihud-116-fabric
6pkgver="0.19.0.dev.20201103.184029"
7pkgrel=1
8pkgdesc="A client-side mod that allows displaying various info lines on the screen "
9arch=('any')
10url="https://masa.dy.fi/mcmods/client_mods/"
11license=('LGPL')
12makedepends=('wget' 'jq')
13source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
14sha1sums=('SKIP')
15
16pkgver() {
17 cd $srcdir
18 cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
19}
20
21build() {
22 wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"url\"]")
23}
24
25package() {
26 install -d -m 755 "${pkgdir}/usr/share/minecraft"
27
28 cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"filename\"]") \
29 "${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.jar"
30}
31

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion