mc-tweakeroo-117-fabric

maintainer eatmyvenom · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD fetches a manifest JSON from masa.dy.fi (the personal/project host of the well-known Minecraft modder 'masady', author of mods like MaLiLib, Litematica, Tweakeroo etc.), which is a legitimate but unofficial/personal host. The real concern is architectural: the manifest is downloaded with a pinned sha1sum, but then a second URL is extracted from that manifest at build time and fetched with wget — with no integrity check on the resulting JAR. If masa.dy.fi were compromised or the manifest tampered with (e.g. via MITM, since the sha1 only covers the initial manifest fetch), an arbitrary JAR could be downloaded and installed. The JAR is executed code placed into the Minecraft mods directory. This is a genuine supply-chain concern (no checksum on the executed artifact), though the host itself is the legitimate upstream for these mods. The pattern of fetching a secondary artifact without integrity verification keeps this at MEDIUM rather than clean.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD fetches a manifest JSON from masa.dy.fi (the personal/project host of the well-known Minecraft modder 'masady', author of mods like MaLiLib, Litematica, Tweakeroo etc.), which is a legitimate but unofficial/personal host. The real concern is architectural: the manifest is downloaded with a pinned sha1sum, but then a second URL is extracted from that manifest at build time and fetched with wget — with no integrity check on the resulting JAR. If masa.dy.fi were compromised or the manifest tampered with (e.g. via MITM, since the sha1 only covers the initial manifest fetch), an arbitrary JAR could be downloaded and installed. The JAR is executed code placed into the Minecraft mods directory. This is a genuine supply-chain concern (no checksum on the executed artifact), though the host itself is the legitimate upstream for these mods. The pattern of fetching a secondary artifact without integrity verification keeps this at MEDIUM rather than clean.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
2
3_modname=tweakeroo
4_mcver="1.17-snapshot-21w05a"
5_modloader="fabric"
6pkgname=mc-tweakeroo-117-fabric
7pkgver="0.10.0.dev.20201218.030023"
8pkgrel=1
9pkgdesc="a client-side mod, which adds a whole bunch of various different tweaks to the game."
10arch=('any')
11url="https://masa.dy.fi/mcmods/client_mods/"
12license=('LGPL')
13makedepends=('wget' 'jq')
14source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
15sha1sums=('3b3c19c94ad38288f78222b4c72847f44df81b34')
16
17pkgver() {
18 cd $srcdir
19 cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
20}
21
22build() {
23 wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"url\"]")
24}
25
26package() {
27 install -d -m 755 "${pkgdir}/usr/share/minecraft"
28
29 cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"filename\"]") \
30 "${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.jar"
31}
32

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion