todesk-bin

maintainer witt.9099 · 11 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads and installs prebuilt proprietary binaries (ToDesk remote desktop software) directly from dl.todesk.com, which is the official vendor download host for ToDesk. The binaries are executed/installed on the system and include bundled shared libraries (.so files). While dl.todesk.com appears to be the legitimate official distribution channel for this Chinese remote desktop application (matching the official website todesk.com), it is still a vendor-controlled binary distribution rather than source built from a trusted code repository. The sha256sums provide integrity checking. The main concern is that this is a closed-source remote desktop application with system-level access (systemd service, bundled libs) from a proprietary vendor host — if the host were compromised or the vendor acted maliciously, arbitrary code execution would result. This is a genuine medium-risk supply-chain concern typical of binary AUR packages from proprietary vendors, not a false positive, though it is not clearly malicious.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:29 source_x86_64=("https://dl.todesk.com/linux/${_pkgname}-v${pkgver}-amd64.deb")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads and installs prebuilt proprietary binaries (ToDesk remote desktop software) directly from dl.todesk.com, which is the official vendor download host for ToDesk. The binaries are executed/installed on the system and include bundled shared libraries (.so files). While dl.todesk.com appears to be the legitimate official distribution channel for this Chinese remote desktop application (matching the official website todesk.com), it is still a vendor-controlled binary distribution rather than source built from a trusted code repository. The sha256sums provide integrity checking. The main concern is that this is a closed-source remote desktop application with system-level access (systemd service, bundled libs) from a proprietary vendor host — if the host were compromised or the vendor acted maliciously, arbitrary code execution would result. This is a genuine medium-risk supply-chain concern typical of binary AUR packages from proprietary vendors, not a false positive, though it is not clearly malicious.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: yjun <jerrysteve1101 at gmail dot com>
2# Maintainer: witt <1989161762 at qq dot com>
3
4pkgname=todesk-bin
5_pkgname=${pkgname%-bin}
6_binaryname=ToDesk
7pkgver=4.8.6.2
8pkgrel=1
9pkgdesc="Remote control and team work"
10arch=('x86_64' 'aarch64')
11url="https://www.todesk.com/"
12license=('custom')
13depends=('gtk3'
14 'libappindicator-gtk3'
15 'noto-fonts-cjk')
16makedepends=('wget' 'tar')
17provides=("${_pkgname}")
18conflicts=("${_pkgname}")
19# !strip: strip could generate error.
20# --->
21# strip: error: the input file './opt/todesk/bin/todesk' has no sections
22# strip: error: the input file './opt/todesk/bin/todeskd' has no sections
23#
24# emptydirs: leave /opt/todesk/config empty dir
25options=('!strip' 'emptydirs')
26DLAGENTS=("https::/usr/bin/wget -U 'Mozilla' -O %o %u")
27install="${_pkgname}.install"
28source=('license.html')
29source_x86_64=("https://dl.todesk.com/linux/${_pkgname}-v${pkgver}-amd64.deb")
30source_aarch64=("https://dl.todesk.com/linux/${_pkgname}-v4.7.2.0-arm64.deb")
31source_armv7h=("https://dl.todesk.com/linux/${_pkgname}-v${pkgver}-armv7l.deb")
32sha256sums=('402b2db2586c723af990beb0f96249b9680880f4f30e58a7cbe7cbd20b979a0b')
33sha256sums_x86_64=('b3f2af7fc120948903df3aa455955cb5823fb5c1f5ec7dca17ac8a4cba53c808')
34sha256sums_aarch64=('07a1239d0ea6b94f24e12b446d39cf6b23747b2e52f09c3dff50daa1394ae0b5')
35
36_install() {
37 find ${@: 2} -type f -exec install -Dm$1 {} ${pkgdir}/{} \;
38}
39
40build() {
41 mkdir -p ${srcdir}/build
42
43 [ -f "${srcdir}/data.tar.xz" ] && tar -xf ${srcdir}/data.tar.xz -C ${srcdir}/build
44 [ -f "${srcdir}/data.tar.zst" ] && tar -xf ${srcdir}/data.tar.zst -C ${srcdir}/build
45}
46
47package() {
48 cd ${srcdir}/build/
49
50 # binary wrapper
51 install -Dm755 usr/local/bin/${_pkgname} -t ${pkgdir}/usr/bin/
52
53 # binary & scripts
54 install -Dm755 opt/${_pkgname}/bin/${_binaryname}{,_Service,_Session} -t ${pkgdir}/opt/${_pkgname}/bin
55 install -Dm755 opt/${_pkgname}/bin/CrashReport -t ${pkgdir}/opt/${_pkgname}/bin
56
57 # lib
58 # bundled libaray for hardware video encode
59 cp -a opt/${_pkgname}/bin/*.so* ${pkgdir}/opt/${_pkgname}/bin/
60 # _install 644 opt/${_pkgname}/bin -name libzrtc.so
61
62 # icon
63 # find opt/${_pkgname}/res -maxdepth 1 -type f -exec install -Dm644 {} ${pkgdir}/{} \;
64 _install 644 opt/${_pkgname}/res -maxdepth 1
65
66 # config
67 # empty dir
68 install -dm755 ${pkgdir}/opt/${_pkgname}/config
69
70 # desktop entry
71 install -Dm644 usr/share/applications/${_pkgname}.desktop -t ${pkgdir}/usr/share/applications
72
73 # systemd service
74 install -Dm644 etc/systemd/system/${_pkgname}d.service -t ${pkgdir}/usr/lib/systemd/system
75
76 # icon
77 # find usr/share/icons -type f -exec install -Dm644 {} ${pkgdir}/{} \;
78 _install 644 usr/share/icons
79
80 # license
81 install -Dm644 ${srcdir}/license.html -t ${pkgdir}/usr/share/licenses/${pkgname}/
82}
83# vim: set sw=2 ts=2 et:
84

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion