PyPI · pypi.org
darwin-agentic-cloud
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 3.0.4
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · darwin_agentic_cloud-3.0.4/infra/aws_runner/batch_deploy.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · darwin_agentic_cloud-3.0.4/infra/aws_runner/batch_runner.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · darwin_agentic_cloud-3.0.4/infra/aws_runner/deploy.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · darwin_agentic_cloud-3.0.4/darwin/agenticcloud/router.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.0.4 | High risk | 70 | 2026-05-30 |
3.0.3 | High risk | 70 | 2026-05-30 |
3.0.2 | High risk | 70 | 2026-05-30 |
3.0.1 | High risk | 70 | 2026-05-30 |
3.0.0 | High risk | 70 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi darwin-agentic-cloud==3.0.4