Maven · repo1.maven.org
io.zahori:zahori-framework
Java Base64 Combo: Base64.decode combined with network / process / defineClass — classic obfuscated payload.
Why PkgRadar flagged 0.2.40-appium
| Severity | Signal | Evidence |
|---|---|---|
| high | Java Base64 Combo | Base64.decode combined with network / process / defineClass — classic obfuscated payload. · io/zahori/framework/utils/video/CDPScreenRecorder.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · io/zahori/framework/core/Browser.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · io/zahori/framework/utils/video/AndroidScreenRecorder.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · io/zahori/framework/utils/video/CDPScreenRecorder.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.2.40-appium | High risk | 37 | 2026-06-10 |
Block this in CI
pkgradar gate --ecosystem maven io.zahori:[email protected]