unlz-gba

maintainer Sterophonick · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The package downloads a prebuilt Windows executable (unLZ-GBA.exe) from an S3 bucket (s3-external-1.amazonaws.com/romhacking-hacks/) that is not an official vendor release host. While romhacking.net is a well-known community site and this S3 bucket appears to be its asset storage, the executable is a prebuilt binary with no source code, installed and run via Wine. The MD5 checksum for the zip is provided (249eee2bbfba42d0dc71beb50f117520), which provides some integrity protection, but the wrapper script, desktop file, and icon all have 'SKIP' checksums. The core concern is a prebuilt binary from a third-party S3 host with no source build — if the S3 object is replaced, users would execute arbitrary code via Wine. This is a genuine medium-severity supply-chain concern: not clearly malicious, but an unofficial binary host with a precompiled executable that gets executed on the user's system.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=(https://s3-external-1.amazonaws.com/romhacking-hacks/utilities/%5B362%5Dunlz-gba.zip
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The package downloads a prebuilt Windows executable (unLZ-GBA.exe) from an S3 bucket (s3-external-1.amazonaws.com/romhacking-hacks/) that is not an official vendor release host. While romhacking.net is a well-known community site and this S3 bucket appears to be its asset storage, the executable is a prebuilt binary with no source code, installed and run via Wine. The MD5 checksum for the zip is provided (249eee2bbfba42d0dc71beb50f117520), which provides some integrity protection, but the wrapper script, desktop file, and icon all have 'SKIP' checksums. The core concern is a prebuilt binary from a third-party S3 host with no source build — if the S3 object is replaced, users would execute arbitrary code via Wine. This is a genuine medium-severity supply-chain concern: not clearly malicious, but an unofficial binary host with a precompiled executable that gets executed on the user's system.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Sterophonick
2
3pkgname=unlz-gba
4_pkgname='unlz-gba'
5pkgver=1.0Beta
6pkgrel=1
7pkgdesc='Scan GBA ROMs for LZ77 compressed graphics'
8arch=(x86_64 i686)
9depends=('wine' 'winetricks')
10source=(https://s3-external-1.amazonaws.com/romhacking-hacks/utilities/%5B362%5Dunlz-gba.zip
11 unlz-gba
12 unlz-gba.desktop
13 unlz-gba.png)
14md5sums=('249eee2bbfba42d0dc71beb50f117520'
15 'SKIP'
16 'SKIP'
17 'SKIP')
18
19
20package() {
21 cd $srcdir
22 install -Dm755 unlz-gba $pkgdir/usr/bin/unlz-gba
23 install -Dm644 unlz-gba.desktop $pkgdir/usr/share/applications/unlz-gba.desktop
24 install -Dm644 unlz-gba.png $pkgdir/usr/share/pixmaps/unlz-gba.png
25
26 mkdir -p $pkgdir/usr/share/unlz-gba
27
28 install -Dm644 unLZ-GBA.exe $pkgdir/usr/share/unlz-gba
29 install -Dm644 readme.txt $pkgdir/usr/share/unlz-gba
30}
31

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion