PyPI · pypi.org
bingo-ai
DNS / OAST exfiltration: matched "dig @attacker.com $("
Why PkgRadar flagged 1.0.9
| Severity | Signal | Evidence |
|---|---|---|
| high | DNS / OAST exfiltration | matched "dig @attacker.com $(" · bingo_ai-1.0.9/bingo/skills/skills_data.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · bingo_ai-1.0.9/vendor/sqlmap/thirdparty/bottle/bottle.py |
| medium | Py Import Time Eval Exec | Python eval()/exec() called on a string. · bingo_ai-1.0.9/vendor/sqlmap/thirdparty/six/__init__.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.9 | High risk | 89 | 2026-06-11 |
1.0.5 | High risk | 89 | 2026-06-11 |
1.0.4 | High risk | 89 | 2026-06-11 |
1.0.3 | High risk | 89 | 2026-06-11 |
1.0.2 | High risk | 89 | 2026-06-11 |
1.0.0 | High risk | 35 | 2026-06-11 |
Block this in CI
pkgradar gate --ecosystem pypi bingo-ai==1.0.9