tosutil-bin

maintainer faizhasan · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads a prebuilt, unversioned binary directly from bytepluses.com (BytePlus, the international brand of ByteDance's cloud services). While bytepluses.com is a legitimate BytePlus/ByteDance-operated domain and TOS (Torch Object Storage) is a real BytePlus product, the binary is fetched without version pinning in the URL path (no version directory), meaning the remote file could be silently replaced. There is no source code, no build step, and no reproducibility. The sha256sum provides some protection against in-transit tampering but not against the upstream host replacing the binary at the same URL. This is a classic prebuilt-binary-from-vendor pattern: not clearly malicious, but a genuine supply-chain concern since any compromise or silent update of the remote binary would be executed directly on user systems.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=(https://tos-tools.tos-ap-southeast-1.bytepluses.com/linux/amd64/tosutil)
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt, unversioned binary directly from bytepluses.com (BytePlus, the international brand of ByteDance's cloud services). While bytepluses.com is a legitimate BytePlus/ByteDance-operated domain and TOS (Torch Object Storage) is a real BytePlus product, the binary is fetched without version pinning in the URL path (no version directory), meaning the remote file could be silently replaced. There is no source code, no build step, and no reproducibility. The sha256sum provides some protection against in-transit tampering but not against the upstream host replacing the binary at the same URL. This is a classic prebuilt-binary-from-vendor pattern: not clearly malicious, but a genuine supply-chain concern since any compromise or silent update of the remote binary would be executed directly on user systems.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Faiz Hasan <faiz at kopi dot pp dot ua>
2pkgname=tosutil-bin
3_pkgname=tosutil
4pkgver=3.1.4
5pkgrel=1
6pkgdesc="Tosutil is a command-line tool for accessing and managing BytePlus Torch Object Storage (TOS)."
7depends=()
8arch=('x86_64')
9source=(https://tos-tools.tos-ap-southeast-1.bytepluses.com/linux/amd64/tosutil)
10sha256sums=(00b50507d7530cc073ed607a03cc578312a192709e34795bc8176d0d1ef60cde)
11
12package(){
13 install -D -m 755 "${_pkgname}" "${pkgdir}/usr/bin/${_pkgname}"
14}

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion