PyPI · pypi.org
alpi-agent
Py Install Time Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 0.9.4
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Install Time Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · alpi_agent-0.9.4/alpi/alp/setup.py |
| medium | Py Install Time Subprocess | subprocess call — process spawning. · alpi_agent-0.9.4/alpi/alp/setup.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · alpi_agent-0.9.4/alpi/mcp/client.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · alpi_agent-0.9.4/alpi/cli.py |
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('os') — reflection bypass for static checks. · alpi_agent-0.9.4/alpi/llm.py |
| medium | Credential file access | matched ".aws/" · alpi_agent-0.9.4/alpi/tools/read_file.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.9.4 | High risk | 255 | 2026-06-13 |
0.9.3 | High risk | 255 | 2026-06-12 |
0.9.2 | High risk | 255 | 2026-06-12 |
0.9.1 | High risk | 255 | 2026-06-12 |
0.9.0 | High risk | 255 | 2026-06-12 |
0.8.25 | High risk | 255 | 2026-06-12 |
0.8.24 | High risk | 255 | 2026-06-12 |
0.8.23 | High risk | 255 | 2026-06-11 |
0.8.21 | High risk | 255 | 2026-06-11 |
0.8.20 | High risk | 255 | 2026-06-10 |
0.8.19 | High risk | 255 | 2026-06-10 |
0.8.18 | High risk | 255 | 2026-06-10 |
0.8.17 | High risk | 255 | 2026-06-10 |
0.8.15 | High risk | 255 | 2026-06-10 |
0.8.14 | High risk | 255 | 2026-06-10 |
0.8.13 | High risk | 255 | 2026-06-10 |
0.8.12 | High risk | 255 | 2026-06-09 |
0.8.11 | High risk | 255 | 2026-06-09 |
0.8.10 | High risk | 255 | 2026-06-09 |
0.8.9 | High risk | 255 | 2026-06-09 |
0.8.8 | High risk | 255 | 2026-06-09 |
0.8.7 | High risk | 215 | 2026-06-09 |
0.8.6 | High risk | 215 | 2026-06-08 |
0.8.5 | High risk | 215 | 2026-06-07 |
0.8.4 | High risk | 215 | 2026-06-07 |
0.8.3 | High risk | 215 | 2026-06-06 |
0.8.2 | High risk | 215 | 2026-06-05 |
0.8.1 | High risk | 215 | 2026-06-05 |
0.8.0 | High risk | 215 | 2026-06-04 |
0.7.4 | High risk | 215 | 2026-06-04 |
0.7.3 | High risk | 215 | 2026-06-04 |
0.7.2 | High risk | 215 | 2026-06-04 |
0.7.1 | High risk | 215 | 2026-06-03 |
0.7.0 | High risk | 215 | 2026-06-03 |
0.6.37 | High risk | 215 | 2026-06-03 |
0.6.36 | High risk | 215 | 2026-06-02 |
0.6.35 | High risk | 215 | 2026-06-02 |
0.6.34 | High risk | 215 | 2026-06-02 |
0.6.33 | High risk | 215 | 2026-06-02 |
0.6.32 | High risk | 215 | 2026-06-02 |
0.6.31 | High risk | 215 | 2026-05-30 |
0.6.30 | High risk | 215 | 2026-05-30 |
0.6.29 | High risk | 215 | 2026-05-30 |
0.6.28 | High risk | 215 | 2026-05-30 |
0.6.27 | High risk | 215 | 2026-05-30 |
0.6.26 | High risk | 215 | 2026-05-30 |
0.6.25 | High risk | 215 | 2026-05-30 |
0.6.24 | High risk | 215 | 2026-05-30 |
0.6.23 | High risk | 215 | 2026-05-30 |
0.6.22 | High risk | 215 | 2026-05-30 |
0.6.21 | High risk | 215 | 2026-05-30 |
0.6.20 | High risk | 215 | 2026-05-30 |
0.6.19 | High risk | 215 | 2026-05-30 |
0.6.18 | High risk | 215 | 2026-05-30 |
0.6.17 | High risk | 215 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi alpi-agent==0.9.4