PkgRadar

Cargo · crates.io

car-policy

Reverse Shell: matched "/dev/tcp/attacker/443" — reverse-shell shape

Why PkgRadar flagged 0.28.0

SeveritySignalEvidence
highReverse Shellmatched "/dev/tcp/attacker/443" — reverse-shell shape · car-policy-0.28.0/src/inspectors.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.28.0High risk402026-06-20
0.27.0Low risk02026-06-19
0.26.0Low risk02026-06-17
0.25.0Low risk02026-06-16
0.24.1Low risk02026-06-15
0.24.0Low risk02026-06-14
0.23.0Low risk02026-06-06
0.22.1Low risk02026-06-05
0.22.0Low risk02026-06-05
0.21.0Low risk02026-06-04
0.20.0Low risk02026-05-30
0.19.0Low risk02026-05-29

Block this in CI

PkgRadar gates car-policy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]