PkgRadar

PyPI · pypi.org

balancing-services

Remote Payload: matched "curl "

Why PkgRadar flagged 1.15.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · balancing_services-1.15.0/check.sh
mediumRemote Payloadmatched "curl " · balancing_services-1.15.0/generate.sh
mediumRemote Payloadmatched "curl " · balancing_services-1.15.0/test-and-publish.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.15.0High risk252026-06-10
1.14.0High risk252026-06-03
1.13.0Review252026-05-29

Block this in CI

PkgRadar gates balancing-services (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi balancing-services==1.15.0