PkgRadar

PyPI · pypi.org

better-telegram-mcp

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 4.12.7b3

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · better_telegram_mcp-4.12.7b3/scripts/preserve-diacritics.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.12.7b3High risk452026-06-10
4.12.7b2High risk452026-06-10
4.12.7b1High risk452026-06-10
4.12.6Review52026-06-09
4.12.6b1Review52026-06-09
4.12.5Review52026-06-07
4.12.5b1Review52026-06-07
4.12.4Review52026-06-01
4.12.4b1Review52026-06-01
4.12.1Review52026-05-30
4.12.3Review52026-05-29
4.12.2Review52026-05-29
4.12.2b1Review52026-05-29
4.12.1b1Review32026-05-28

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates better-telegram-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi better-telegram-mcp==4.12.7b3