PyPI · pypi.org
cognis-executor
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 0.9.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · cognis_executor-0.9.0/cognis/tools/executor/lsp/install.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · cognis_executor-0.9.0/cognis/tools/executor/document.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.9.0 | High risk | 80 | 2026-06-14 |
0.8.0 | High risk | 80 | 2026-06-10 |
0.7.0 | High risk | 40 | 2026-05-31 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi cognis-executor==0.9.0