virtualhere-server-bin
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source_i686=("https://www.virtualhere.com/sites/default/files/usbserver/vhusbdi386")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads prebuilt proprietary binaries directly from virtualhere.com (the official vendor site) with SKIP'd checksums, then executes them during both the pkgver() and build() phases. While virtualhere.com is the legitimate upstream vendor for VirtualHere USB Server software, the SKIP'd checksums mean there is no integrity verification — if the binary at that URL were silently replaced or the host were compromised, users would receive and execute a malicious binary without any warning. The binary is also executed at pkgver() time (before the package() phase), meaning it runs during the build process itself. This is a real supply-chain concern: executed binary from a vendor host with no checksum pinning. It is not clearly malicious (the host is the legitimate vendor), but the lack of any integrity check on an executed binary warrants medium severity.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Alexey Manukhin <axxapy@gmail.com>
# Systemd service source:
# https://github.com/virtualhere/script/blob/main/install_server
pkgname=virtualhere-server-bin
pkgver=4.8.5
pkgrel=3
pkgdesc="VirtualHere USB Server for Linux Desktop"
OPTIONS=(!strip)
arch=("i686" "x86_64")
url="https://www.virtualhere.com/usb_server_software"
license=("custom")
provides=("virtualhere")
conflicts=("virtualhere")
source=("virtualhere.service" "config.ini")
source_i686=("https://www.virtualhere.com/sites/default/files/usbserver/vhusbdi386")
source_x86_64=("https://www.virtualhere.com/sites/default/files/usbserver/vhusbdx86_64")
md5sums=('32add976088e8a5b2b306e236afd5071' 'd41d8cd98f00b204e9800998ecf8427e')
md5sums_i686=('SKIP')
md5sums_x86_64=('SKIP')
build() {
mv vhusbd* vhusbd
chmod +x vhusbd
./vhusbd -l > LICENSE
}
pkgver() {
chmod +x "${srcdir}/vhusbdx86_64"
"${srcdir}/vhusbdx86_64" --help 2>/dev/null | head -n 1| sed 's/.*\([0-9][0-9]*\.[0-9][0-9]*\.[0-9][0-9]*\).*/\1/'
}
package() {
install -Dm755 vhusbd "${pkgdir}/usr/bin/vhusbd"
install -Dm644 config.ini "${pkgdir}/etc/virtualhere/config.ini"
install -Dm644 virtualhere.service "${pkgdir}/etc/systemd/system/virtualhere.service"
install -Dm644 LICENSE "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |