PkgRadar

PyPI · pypi.org

clawmetry

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.12.518

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · clawmetry-0.12.518/clawmetry/license.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · clawmetry-0.12.518/clawmetry/sync.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.518High risk552026-06-13
0.12.517High risk552026-06-12
0.12.516High risk552026-06-12
0.12.515High risk552026-06-12
0.12.514High risk552026-06-12
0.12.513High risk552026-06-12
0.12.512High risk552026-06-11
0.12.511High risk552026-06-11
0.12.510High risk552026-06-11
0.12.509High risk552026-06-11
0.12.507High risk552026-06-11
0.12.503High risk552026-06-10
0.12.502High risk552026-06-10
0.12.501High risk552026-06-10
0.12.500High risk552026-06-10
0.12.499High risk552026-06-10
0.12.498High risk552026-06-10
0.12.497High risk552026-06-10
0.12.496High risk552026-06-09
0.12.495High risk552026-06-09
0.12.494High risk552026-06-09
0.12.493High risk552026-06-09
0.12.492High risk552026-06-08
0.12.491High risk552026-06-08
0.12.490High risk552026-06-08
0.12.489High risk552026-06-08
0.12.488High risk552026-06-08
0.12.487High risk552026-06-08
0.12.486High risk552026-06-08
0.12.485High risk552026-06-08
0.12.484High risk552026-06-08
0.12.483High risk552026-06-08
0.12.482High risk552026-06-08
0.12.481High risk552026-06-08
0.12.480High risk552026-06-08
0.12.479High risk552026-06-08
0.12.478High risk552026-06-08
0.12.477High risk552026-06-08
0.12.476High risk552026-06-08
0.12.475High risk552026-06-08
0.12.474High risk552026-06-08
0.12.473High risk552026-06-08
0.12.472High risk552026-06-08
0.12.471High risk552026-06-08
0.12.470High risk552026-06-08
0.12.469High risk552026-06-07
0.12.468High risk602026-06-07
0.12.467High risk602026-06-07
0.12.466High risk602026-06-07
0.12.465High risk602026-06-07
0.12.464High risk602026-06-07
0.12.463High risk602026-06-07
0.12.462High risk602026-06-07
0.12.461High risk602026-06-07
0.12.460High risk602026-06-06
0.12.459High risk602026-06-06
0.12.458High risk602026-06-06
0.12.457High risk602026-06-06
0.12.456High risk602026-06-06
0.12.455High risk602026-06-06
0.12.454High risk602026-06-06
0.12.453High risk602026-06-06
0.12.452High risk602026-06-06
0.12.451High risk602026-06-06
0.12.450High risk602026-06-06
0.12.449High risk602026-06-06
0.12.448High risk602026-06-06
0.12.447High risk602026-06-06
0.12.446High risk602026-06-06
0.12.445High risk602026-06-06
0.12.444High risk602026-06-06
0.12.443High risk602026-06-05
0.12.442High risk602026-06-05
0.12.441High risk602026-06-05
0.12.440High risk602026-06-05
0.12.439High risk602026-06-04
0.12.438High risk602026-06-04
0.12.437High risk602026-06-04
0.12.436High risk602026-06-04
0.12.435High risk602026-06-04
0.12.434High risk602026-06-03
0.12.433High risk602026-06-03
0.12.432High risk602026-06-03
0.12.431High risk602026-06-03
0.12.430High risk602026-06-03
0.12.429High risk602026-06-03
0.12.428High risk602026-06-03
0.12.427High risk602026-06-03
0.12.426High risk602026-06-03
0.12.425High risk602026-06-03
0.12.424High risk602026-06-03
0.12.423High risk602026-06-03
0.12.422High risk602026-06-03
0.12.421High risk602026-06-03
0.12.420High risk602026-06-03
0.12.419High risk602026-06-03
0.12.418High risk602026-06-03
0.12.417High risk602026-06-03
0.12.416High risk602026-06-03
0.12.415High risk602026-06-03
0.12.414High risk602026-06-02
0.12.413High risk602026-06-02
0.12.412High risk602026-06-02
0.12.411High risk602026-06-02
0.12.410High risk602026-06-02
0.12.409High risk602026-06-02
0.12.408High risk602026-06-02
0.12.407High risk602026-06-02
0.12.406High risk602026-06-02
0.12.405High risk602026-06-02
0.12.404High risk602026-06-02
0.12.403High risk602026-06-02
0.12.402High risk602026-06-02
0.12.401High risk602026-06-02
0.12.400High risk602026-06-02
0.12.399High risk602026-06-02
0.12.398High risk602026-06-02
0.12.397High risk602026-06-02
0.12.396High risk602026-06-02
0.12.395High risk602026-06-02
0.12.394High risk602026-06-02
0.12.393High risk602026-06-02
0.12.392High risk602026-06-02
0.12.391High risk602026-06-02
0.12.390High risk602026-06-02
0.12.389High risk602026-06-02
0.12.388High risk602026-06-02
0.12.387High risk602026-06-02
0.12.386High risk602026-06-02
0.12.385High risk602026-06-02
0.12.384High risk602026-06-01
0.12.383High risk402026-06-01
0.12.382High risk402026-06-01
0.12.381High risk402026-06-01
0.12.380High risk402026-05-31
0.12.379High risk402026-05-31
0.12.378High risk402026-05-31
0.12.377High risk402026-05-31
0.12.376High risk402026-05-31
0.12.375High risk402026-05-31
0.12.374High risk402026-05-31
0.12.373High risk402026-05-30
0.12.372High risk402026-05-30
0.12.371High risk402026-05-30
0.12.370High risk402026-05-30
0.12.369High risk402026-05-30
0.12.368High risk402026-05-30
0.12.367High risk402026-05-30
0.12.366High risk402026-05-30
0.12.365High risk402026-05-30
0.12.364High risk402026-05-30
0.12.363High risk402026-05-30
0.12.362High risk402026-05-30
0.12.361High risk402026-05-30
0.12.360High risk402026-05-30
0.12.359High risk402026-05-30
0.12.358High risk402026-05-30
0.12.357High risk402026-05-30
0.12.356High risk402026-05-30
0.12.355High risk402026-05-30
0.12.354High risk402026-05-30
0.12.353High risk402026-05-30
0.12.352High risk402026-05-30
0.12.351High risk402026-05-30
0.12.350High risk402026-05-30
0.12.349High risk402026-05-30
0.12.348High risk402026-05-30
0.12.347High risk402026-05-30
0.12.346High risk402026-05-30
0.12.345High risk402026-05-30
0.12.344High risk402026-05-30
0.12.343High risk402026-05-30
0.12.342High risk402026-05-30
0.12.341High risk402026-05-30
0.12.340High risk402026-05-30
0.12.339High risk402026-05-30
0.12.338High risk402026-05-30
0.12.337High risk402026-05-30
0.12.336High risk402026-05-30
0.12.335High risk402026-05-30
0.12.334High risk402026-05-30
0.12.333High risk402026-05-30
0.12.332High risk402026-05-30
0.12.331High risk402026-05-30
0.12.330High risk402026-05-30
0.12.329High risk402026-05-30

Block this in CI

PkgRadar gates clawmetry (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi clawmetry==0.12.518