netcatty

LOW
maintainer zxp19821005 0 votes scanned 2026-10-07 06:10:08.268905
View on AUR
Why flagged

The PKGBUILD builds from the project's own GitHub source with checksums; 'npm add async-exit-hook' injects an undeclared but well-known npm package as a build workaround, and npx calls execute standard Electron build tools (vite, electron-rebuild, electron-builder) already present in node_modules — no obfuscation, exfiltration, or clearly malicious behavior observed.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The PKGBUILD builds from the project's own GitHub source with checksums; 'npm add async-exit-hook' injects an undeclared but well-known npm package as a build workaround, and npx calls execute standard Electron build tools (vite, electron-rebuild, electron-builder) already present in node_modules — no obfuscation, exfiltration, or clearly malicious behavior observed.

2 higher static findings superseded - not the current verdict (shown for transparency)
Medium npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:98 npm add async-exit-hook
Medium npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:107 npx vite build
  • PKGBUILD:110 npx electron-rebuild --force --arch arm64 -w "node-pty,@serialport/bindings-cpp"
  • PKGBUILD:113 npx electron-rebuild --force --arch x64 -w "node-pty,@serialport/bindings-cpp"

PKGBUILD

4 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=netcatty
3_pkgname=Netcatty
4pkgver=1.1.83
5_electronversion=42
6_nodeversion=24
7pkgrel=1
8pkgdesc="AI-Powered SSH Client, SFTP Browser & Terminal Manager."
9arch=(
10 'aarcb64'
11 'x86_64'
12)
13url="https://netcatty.app/"
14_ghurl="https://github.com/binaricat/Netcatty"
15license=('GPL-3.0-or-later')
16depends=(
17 "electron${_electronversion}"
18 'python'
19)
20makedepends=(
21 'npm'
22 'nvm'
23 'git'
24 'gendesk'
25 'jq'
26)
27source=(
28 "${pkgname}-${pkgver}.tar.gz::${_ghurl}/archive/refs/tags/v${pkgver}.tar.gz"
29 "${pkgname}.sh"
30)
31sha256sums=('ca9f54ff99450788ff47c5c7f723da2332659062dbd43e80a14cd0f78e584573'
32 'bd5358d8f323d3c2c2f0733364ee4ea55f551dd86ba0be2a76846210b60897fc')
33_ensure_local_nvm() {
34 local NVM_DIR="${srcdir}/.nvm"
35 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
36 nvm install "${_nodeversion}"
37 nvm use "${_nodeversion}"
38}
39_get_project_dir() {
40 local d
41 while IFS= read -r d; do
42 find "$d" -name "package.json" ! -path "*/node_modules/*" 2>/dev/null | grep -q . && { echo "$d"; return; }
43 done < <(find "${srcdir}" -maxdepth 1 -mindepth 1 -type d ! -name '.*')
44}
45_get_app_dir() {
46 find "${srcdir}" -type f -name "resources.pak" -print 2>/dev/null | while read f; do [ -d "${f%/*}/resources" ] && echo "${f%/*}" && break; done
47}
48_set_build_env() {
49 export ELECTRON_DIST="/usr/lib/electron${_electronversion}"
50 export ELECTRON_OVERRIDE_DIST_PATH="${ELECTRON_DIST}"
51 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
52 export ELECTRON_BUILDER_OFFLINE=true
53 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/^v//')"
54 export HOME="${srcdir}/.home"
55 export XDG_CACHE_HOME="${HOME}/.cache"
56 export XDG_CONFIG_HOME="${HOME}/.config"
57 export XDG_DATA_HOME="${HOME}/.local/share"
58 export npm_config_cache="${HOME}/.npm_cache"
59 export COREPACK_NPM_REGISTRY="${COREPACK_NPM_REGISTRY:-${NPM_CONFIG_REGISTRY:-https://registry.npmjs.org}}"
60 export COREPACK_HOME="${HOME}/.corepack"
61 export npm_config_audit=false
62 export npm_config_registry="${NPM_CONFIG_REGISTRY:-${npm_config_registry:-https://registry.npmjs.org}}"
63 export npm_config_build_from_source=true
64 mkdir -p "${HOME}" "${npm_config_cache}" "${COREPACK_HOME}"
65}
66_get_electron_version() {
67 _elec_ver=$(find "$(_get_project_dir)" -name "package.json" ! -path "*/node_modules/*" -print \
68 | xargs -I{} jq -r '(.devDependencies.electron // .dependencies.electron) // empty' {} 2>/dev/null \
69 | grep -v '^$' | sed 's/^[^0-9]*//' | head -1)
70 [[ -z "${_elec_ver}" ]] && return 1
71 echo -e "The electron version is: \033[1;31m${_elec_ver%%.*}\033[0m"
72}
73prepare() {
74 cd "$(_get_project_dir)"
75 _get_electron_version
76 sed -i -e "
77 s/@electronversion@/${_electronversion}/g
78 s/@appname@/${pkgname}/g
79 s/@runname@/app.asar/g
80 s/@cfgdirname@/${pkgname}/g
81 " "${srcdir}/${pkgname}.sh"
82 gendesk -q -f -n \
83 --pkgname="${pkgname}" \
84 --pkgdesc="${pkgdesc}" \
85 --categories="System;Utility" \
86 --name="${_pkgname}" \
87 --exec="${pkgname} %U"
88 _ensure_local_nvm
89 _set_build_env
90 jq --arg ver "${SYSTEM_ELECTRON_VERSION}" '.devDependencies.electron = $ver' package.json > package.json.tmp && mv package.json.tmp package.json
91 find electron -type f -exec sed -i "s/process.resourcesPath/\'\/usr\/lib\/${pkgname}\'/g" {} +
92 cat > noop-hook.cjs << 'EOF'
93module.exports = function() {};
94module.exports.default = module.exports;
95EOF
96 export NODE_ENV=development
97 npm install
98 npm add async-exit-hook
99}
100build() {
101 cd "$(_get_project_dir)"
102 _ensure_local_nvm
103 _set_build_env
104 export NODE_ENV=production
105 export NODE_OPTIONS=--disable-warning=DEP0190
106 npm run build:plugin-packages
107 npx vite build
108 case "${CARCH}" in
109 aarch64)
110 npx electron-rebuild --force --arch arm64 -w "node-pty,@serialport/bindings-cpp"
111 ;;
112 x86_64)
113 npx electron-rebuild --force --arch x64 -w "node-pty,@serialport/bindings-cpp"
114 ;;
115 esac
116 npm exec -c "electron-builder --linux dir -c.electronDist=${ELECTRON_DIST} -c.beforePack=./noop-hook.cjs -c.npmRebuild=false --config electron-builder.config.cjs"
117 local _app_dir="$(_get_app_dir)"
118 case "${CARCH}" in
119 aarch64) _archrem=x64 ;;
120 x86_64) _archrem=arm ;;
121 esac
122 find "${_app_dir}/resources/app.asar.unpacked" -type d \
123 \( -name "darwin*" -o -name "win32*" -o -name "*${_archrem}"* \) \
124 -exec rm -rf {} +
125}
126package() {
127 install -Dm755 "${srcdir}/${pkgname}.sh" "${pkgdir}/usr/bin/${pkgname}"
128 install -Dm755 -d "${pkgdir}/usr/lib/${pkgname}"
129 local _app_dir="$(_get_app_dir)"
130 cp -a "${_app_dir}/resources/." "${pkgdir}/usr/lib/${pkgname}/"
131 rm -rf "${pkgdir}/usr/lib/${pkgname}/default_app.asar"
132 local _src="$(_get_project_dir)"
133 _icon_sizes=(16x16 32x32 48x48 64x64 128x128 256x256 512x512)
134 for _icons in "${_icon_sizes[@]}";do
135 install -Dm644 "${_src}/build/icons/${_icons}.png" \
136 "${pkgdir}/usr/share/icons/hicolor/${_icons}/apps/${pkgname%-git}.png"
137 done
138 install -Dm644 "${_src}/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
139 install -Dm644 "${_src}/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
140}
141

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 06:10:08 Low 4
2026-10-07 06:05:09 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion