smart-contract-obfuscator-git

maintainer zxp19821005 · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged This PKGBUILD follows a common pattern seen in many AUR Electron app packages maintained by zxp19821005. The npm install and npx/electron-vite build steps are standard Node.js/Electron build toolchain operations — they install declared dependencies from package.json (which is part of the cloned git source) and run the build tool. The source is fetched directly from the official upstream GitHub repository via git+https. The npm install reads from the project's own package.json/package-lock.json, not from an arbitrary external location. The 'npm add -D rollup' adds a build dependency locally. The CN mirror substitution is a well-known pattern for Chinese maintainers to work around network restrictions and only affects the registry URL, not the package integrity. electron-vite and electron-builder are standard Electron build tools. There is no binary fetched from an unofficial host, no obfuscated payload, and no exfiltration. The main concern is that npm install fetches packages at build time without pinned hashes in the PKGBUILD itself, but this is standard practice for source-built AUR packages and the lock file in the repo provides some integrity. This is sloppy/non-standard (no offline source tarball) but not a genuine supply-chain threat beyond what any npm-based AUR package presents.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 75%): This PKGBUILD follows a common pattern seen in many AUR Electron app packages maintained by zxp19821005. The npm install and npx/electron-vite build steps are standard Node.js/Electron build toolchain operations — they install declared dependencies from package.json (which is part of the cloned git source) and run the build tool. The source is fetched directly from the official upstream GitHub repository via git+https. The npm install reads from the project's own package.json/package-lock.json, not from an arbitrary external location. The 'npm add -D rollup' adds a build dependency locally. The CN mirror substitution is a well-known pattern for Chinese maintainers to work around network restrictions and only affects the registry URL, not the package integrity. electron-vite and electron-builder are standard Electron build tools. There is no binary fetched from an unofficial host, no obfuscated payload, and no exfiltration. The main concern is that npm install fetches packages at build time without pinned hashes in the PKGBUILD itself, but this is standard practice for source-built AUR packages and the lock file in the repo provides some integrity. This is sloppy/non-standard (no offline source tarball) but not a genuine supply-chain threat beyond what any npm-based AUR package presents.

2 higher static findings superseded - not the current verdict (shown for transparency)
MEDIUM npm/yarn/pnpm install of an undeclared external package npm_install_external

Runs `npm/yarn/pnpm install <package>` for a package not in source=(), pulling unpinned, unreviewed code at build time. Severity downgraded: the package declares/looks like a Node.js consumer, where build-time installs are expected.

  • PKGBUILD:77 NODE_ENV=development npm add -D rollup
MEDIUM npx/bunx/deno executes a remote package remote_code_tool

`npx`/`bunx`/`pnpm dlx`/`deno run <url>` downloads AND runs a remote package at build time — the moral equivalent of piping a download into a shell. Severity downgraded: Node.js consumer context.

  • PKGBUILD:82 NODE_ENV=production npx electron-vite build

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: zxp19821005 <zxp19821005 at 163 dot com>
2pkgname=smart-contract-obfuscator-git
3_pkgname=SCO
4pkgver=setup.r0.g427ee3f
5_electronversion=28
6_nodeversion=20
7pkgrel=1
8pkgdesc="A visualized, highly integrated, all-in-one code obfuscation tool specifically for smart contract source code. Support visual analysis of code structure, code obfuscation, code security assessment. Electron based development.(Use system-wide electron)"
9arch=('any')
10url="https://github.com/JKerbin/Smart-Contract-Obfuscator"
11license=('Apache-2.0')
12conflicts=("${pkgname%-git}")
13provides=("${pkgname%-git}=${pkgver%.r*}")
14depends=(
15 "electron${_electronversion}"
16)
17makedepends=(
18 'gendesk'
19 'npm'
20 'nvm'
21 'git'
22 'curl'
23)
24source=(
25 "${pkgname%-git}.git::git+${url}"
26 "${pkgname%-git}.sh"
27)
28sha256sums=('SKIP'
29 '291f50480f5a61bc9c68db7d44cd0412071128706baa868a9cb854f8779a1980')
30pkgver() {
31 cd "${srcdir}/${pkgname%-git}.git"
32 set -o pipefail
33 git describe --long --tags --abbrev=7 | sed 's/\([^-]*-g\)/r\1/;s/-/./g;s/v//g' ||
34 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
35}
36_ensure_local_nvm() {
37 local NVM_DIR="${srcdir}/.nvm"
38 source /usr/share/nvm/init-nvm.sh || [[ $? != 1 ]]
39 nvm install "${_nodeversion}"
40 nvm use "${_nodeversion}"
41}
42prepare() {
43 cd "${srcdir}/${pkgname%-git}.git"
44 sed -i -e "
45 s/@electronversion@/${_electronversion}/g
46 s/@appname@/${pkgname%-git}/g
47 s/@runname@/app.asar/g
48 s/@cfgdirname@/${_pkgname}/g
49 s/@options@/env ELECTRON_OZONE_PLATFORM_HINT=auto/g
50 " "${srcdir}/${pkgname%-git}.sh"
51 _ensure_local_nvm
52 gendesk -q -f -n \
53 --pkgname="${pkgname%-git}" \
54 --pkgdesc="${pkgdesc}" \
55 --categories="Development" \
56 --name="${_pkgname}" \
57 --exec="${pkgname%-git} %U"
58 export ELECTRON_SKIP_BINARY_DOWNLOAD=1
59 export SYSTEM_ELECTRON_VERSION="$(electron${_electronversion} -v | sed 's/v//g')"
60 HOME="${srcdir}/.electron-gyp"
61 {
62 echo -e '\n'
63 #echo 'build_from_source=true'
64 echo "cache=${srcdir}/.npm_cache"
65 echo "maxsockets=10"
66 } >> .npmrc
67 if [[ "$(curl -s ipinfo.io/country)" == *"CN"* ]]; then
68 {
69 echo 'registry=https://registry.npmmirror.com'
70 echo 'electron_mirror=https://registry.npmmirror.com/-/binary/electron/'
71 echo 'electron_builder_binaries_mirror=https://registry.npmmirror.com/-/binary/electron-builder-binaries/'
72 } >> .npmrc
73 find ./ -type f -name "package-lock.json" -exec sed -i "s/registry.npmjs.org/registry.npmmirror.com/g" {} +
74 fi
75 sed -i "s/\"electron\": \"[^\"]*\"/\"electron\": \"${SYSTEM_ELECTRON_VERSION}\"/g" package.json
76 NODE_ENV=development npm install
77 NODE_ENV=development npm add -D rollup
78}
79build() {
80 cd "${srcdir}/${pkgname%-git}.git"
81 local electronDist="/usr/lib/electron${_electronversion}"
82 NODE_ENV=production npx electron-vite build
83 NODE_ENV=production npm exec -c "electron-builder --linux dir -c.electronDist=${electronDist} --config electron-builder.yml"
84}
85package() {
86 install -Dm755 "${srcdir}/${pkgname%-git}.sh" "${pkgdir}/usr/bin/${pkgname%-git}"
87 install -Dm644 "${srcdir}/${pkgname%-git}.git/dist/linux-"*/resources/app.asar -t "${pkgdir}/usr/lib/${pkgname%-git}"
88 cp -Pr --no-preserve=ownership "${srcdir}/${pkgname%-git}.git/dist/linux-"*/resources/app.asar.unpacked "${pkgdir}/usr/lib/${pkgname%-git}"
89 install -Dm644 "${srcdir}/${pkgname%-git}.git/${pkgname%-git}.desktop" -t "${pkgdir}/usr/share/applications"
90 install -Dm644 "${srcdir}/${pkgname%-git}.git/icon.png" "${pkgdir}/usr/share/pixmaps/${pkgname%-git}.png"
91 install -Dm644 "${srcdir}/${pkgname%-git}.git/LICENSE" -t "${pkgdir}/usr/share/licenses/${pkgname}"
92}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 3
2026-08-02 00:16:08 LOW 3
2026-08-01 00:11:18 LOW 3
2026-07-31 00:14:10 LOW 3
2026-07-30 00:17:23 LOW 3
2026-07-29 00:25:53 LOW 3
2026-07-28 00:07:28 LOW 3
2026-07-27 00:24:32 LOW 3
2026-07-26 00:07:32 LOW 3
2026-07-25 00:13:44 LOW 3
2026-07-24 00:02:28 LOW 3
2026-07-23 00:14:47 LOW 3
2026-07-22 00:29:32 LOW 3
2026-07-21 00:24:15 LOW 3
2026-07-20 00:19:49 LOW 3
2026-07-19 00:17:08 LOW 3
2026-07-18 00:14:48 LOW 3
2026-07-17 00:06:16 LOW 3
2026-07-16 00:05:41 LOW 3
2026-07-15 00:09:25 LOW 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion