PkgRadar

PyPI · pypi.org

clawbench-eval

Known Indicator Filename: clawbench_eval-0.6.0/src/clawbench/runtime/chrome-extension/stealth.js

Why PkgRadar flagged 0.6.0

SeveritySignalEvidence
highKnown Indicator Filenameclawbench_eval-0.6.0/src/clawbench/runtime/chrome-extension/stealth.js · clawbench_eval-0.6.0/src/clawbench/runtime/chrome-extension/stealth.js
highCredential File Packagedclawbench_eval-0.6.0/.env · clawbench_eval-0.6.0/.env
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · clawbench_eval-0.6.0/src/clawbench/runtime/extension-server/server.py
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/base/entrypoint.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/browser-use/run-browser-use.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/claude-code/run-claude-code.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/claw-code/run-claw-code.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/codex/run-codex.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/harbor/run-harbor.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/hermes/run-hermes.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/openclaw/run-openclaw.sh
mediumRemote Payloadmatched "curl " · clawbench_eval-0.6.0/src/clawbench/runtime/harnesses/opencode/run-opencode.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.0High risk1602026-06-05

Block this in CI

PkgRadar gates clawbench-eval (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi clawbench-eval==0.6.0