PkgRadar

PyPI · pypi.org

claude-mpm

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 6.5.41

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · claude_mpm-6.5.41/src/claude_mpm/services/agents/recommender.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · claude_mpm-6.5.41/src/claude_mpm/mcp/archive/google_workspace_server.py

Scanned versions

VersionVerdictScoreScanned (UTC)
6.5.41High risk522026-06-12
6.5.40High risk522026-06-12
6.5.39High risk522026-06-12
6.5.38High risk522026-06-12
6.5.37High risk522026-06-12
6.5.36High risk522026-06-12
6.5.35High risk522026-06-12
6.5.34High risk522026-06-12
6.5.33High risk522026-06-11
6.5.32High risk522026-06-11
6.5.30High risk522026-06-11
6.5.29High risk522026-06-11
6.5.28High risk522026-06-10
6.5.27High risk522026-06-10
6.5.26High risk522026-06-10
6.5.25High risk522026-06-09
6.5.24High risk522026-06-09
6.5.23High risk242026-06-09
6.5.22High risk242026-06-08
6.5.21High risk242026-06-07
6.5.20High risk242026-06-06
6.5.19High risk242026-06-05
6.5.18High risk242026-06-05
6.5.17High risk242026-06-04
6.5.16High risk242026-06-04
6.5.15High risk242026-06-04
6.5.14High risk242026-06-04
6.5.13High risk242026-06-03
6.5.12High risk242026-06-03
6.5.11High risk242026-06-02
6.5.10High risk242026-06-02
6.5.9High risk242026-06-02
6.5.8High risk242026-06-02
6.5.7High risk242026-06-01
6.5.6High risk242026-06-01
6.5.5High risk242026-06-01
6.5.4High risk242026-06-01
6.5.3High risk242026-06-01
6.5.2High risk242026-06-01
6.5.1High risk242026-06-01
6.5.0High risk242026-05-30
6.4.17High risk242026-05-30
6.4.16High risk242026-05-30
6.4.15High risk242026-05-30
6.4.14High risk242026-05-30
6.4.13High risk242026-05-30
6.4.12High risk242026-05-30

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates claude-mpm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi claude-mpm==6.5.41