PkgRadar

PyPI · pypi.org

aibrain

Webhook Exfil Endpoint: matched "requestbin.com"

Why PkgRadar flagged 1.8.7

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "requestbin.com" · aibrain/core/the_hands.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · aibrain/tools/compress/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · mcp_peer_discovery.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · mcp_server.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · aibrain/lucy_agent.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · aibrain/core/watchdog.py
mediumRemote Payloadmatched "curl " · aibrain_networking.py
mediumCredential file accessmatched "AWS_ACCESS_KEY" · aibrain/core/the_hands.py
mediumCredential file accessmatched ".ssh/" · aibrain/tools/builtin.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.7High risk2842026-06-01

Block this in CI

PkgRadar gates aibrain (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aibrain==1.8.7