virtualhere-server-bin

maintainer axp · 3 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The PKGBUILD downloads prebuilt proprietary binaries directly from virtualhere.com (the official vendor site) with SKIP'd checksums, then executes them during both the pkgver() and build() phases. While virtualhere.com is the legitimate upstream vendor for VirtualHere USB Server software, the SKIP'd checksums mean there is no integrity verification — if the binary at that URL were silently replaced or the host were compromised, users would receive and execute a malicious binary without any warning. The binary is also executed at pkgver() time (before the package() phase), meaning it runs during the build process itself. This is a real supply-chain concern: executed binary from a vendor host with no checksum pinning. It is not clearly malicious (the host is the legitimate vendor), but the lack of any integrity check on an executed binary warrants medium severity.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source_i686=("https://www.virtualhere.com/sites/default/files/usbserver/vhusbdi386")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads prebuilt proprietary binaries directly from virtualhere.com (the official vendor site) with SKIP'd checksums, then executes them during both the pkgver() and build() phases. While virtualhere.com is the legitimate upstream vendor for VirtualHere USB Server software, the SKIP'd checksums mean there is no integrity verification — if the binary at that URL were silently replaced or the host were compromised, users would receive and execute a malicious binary without any warning. The binary is also executed at pkgver() time (before the package() phase), meaning it runs during the build process itself. This is a real supply-chain concern: executed binary from a vendor host with no checksum pinning. It is not clearly malicious (the host is the legitimate vendor), but the lack of any integrity check on an executed binary warrants medium severity.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Alexey Manukhin <axxapy@gmail.com>
2
3# Systemd service source:
4# https://github.com/virtualhere/script/blob/main/install_server
5
6pkgname=virtualhere-server-bin
7pkgver=4.8.5
8pkgrel=3
9pkgdesc="VirtualHere USB Server for Linux Desktop"
10OPTIONS=(!strip)
11arch=("i686" "x86_64")
12url="https://www.virtualhere.com/usb_server_software"
13license=("custom")
14provides=("virtualhere")
15conflicts=("virtualhere")
16source=("virtualhere.service" "config.ini")
17source_i686=("https://www.virtualhere.com/sites/default/files/usbserver/vhusbdi386")
18source_x86_64=("https://www.virtualhere.com/sites/default/files/usbserver/vhusbdx86_64")
19md5sums=('32add976088e8a5b2b306e236afd5071' 'd41d8cd98f00b204e9800998ecf8427e')
20md5sums_i686=('SKIP')
21md5sums_x86_64=('SKIP')
22
23build() {
24 mv vhusbd* vhusbd
25 chmod +x vhusbd
26 ./vhusbd -l > LICENSE
27}
28
29pkgver() {
30 chmod +x "${srcdir}/vhusbdx86_64"
31 "${srcdir}/vhusbdx86_64" --help 2>/dev/null | head -n 1| sed 's/.*\([0-9][0-9]*\.[0-9][0-9]*\.[0-9][0-9]*\).*/\1/'
32}
33
34package() {
35 install -Dm755 vhusbd "${pkgdir}/usr/bin/vhusbd"
36 install -Dm644 config.ini "${pkgdir}/etc/virtualhere/config.ini"
37 install -Dm644 virtualhere.service "${pkgdir}/etc/systemd/system/virtualhere.service"
38 install -Dm644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
39}
40

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion