PkgRadar

PyPI · pypi.org

aither-adk

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2.8.1

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · aither_adk-2.8.1/adk/setup.py
mediumPy Install Time Subprocesssubprocess call — process spawning. · aither_adk-2.8.1/adk/shell/plugins/builtins/setup.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · aither_adk-2.8.1/adk/platform/ai/persona_image_system.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · aither_adk-2.8.1/adk/setup_cli.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · aither_adk-2.8.1/adk/shell/repl.py
mediumRemote Payloadmatched "curl " · aither_adk-2.8.1/setup-vllm.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.1High risk1622026-06-13
2.8.0High risk1622026-06-12
2.7.0High risk922026-06-06
2.6.4High risk922026-06-05
2.6.3High risk922026-06-05
2.6.2High risk922026-06-05
2.6.1High risk922026-06-05
2.6.0High risk922026-06-05
2.5.0High risk922026-06-04
2.4.1High risk922026-06-03
2.4.0High risk922026-06-03
2.1.0High risk922026-06-02
2.0.0High risk922026-06-02
1.24.0High risk922026-05-30
1.23.0High risk922026-05-30
1.22.0High risk922026-05-30
1.21.0High risk922026-05-30
1.20.0High risk922026-05-30
1.19.0High risk922026-05-30
1.18.1High risk922026-05-30
1.18.0High risk922026-05-30
1.17.0High risk922026-05-30
1.16.0Review622026-05-30
1.15.0Review622026-05-30

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates aither-adk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi aither-adk==2.8.1