PkgRadar

PyPI · pypi.org

codex-lb

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 1.20.0b1

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · codex_lb-1.20.0b1/scripts/verify_rollout_safe_bridge.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.20.0b1High risk382026-06-04

Block this in CI

PkgRadar gates codex-lb (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi codex-lb==1.20.0b1