PyPI · pypi.org
dreadnode
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 2.0.30
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · dreadnode-2.0.30/dreadnode/app/cli/task.py |
| high | Credential file access | matched "AWS_ACCESS_KEY" · dreadnode-2.0.30/dreadnode/transforms/competitive_parity.py |
| medium | Remote Payload | matched "curl " · dreadnode-2.0.30/dreadnode/transforms/supply_chain.py |
| medium | Credential file access | matched ".ssh/" · dreadnode-2.0.30/dreadnode/scorers/contains.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.0.30 | High risk | 51 | 2026-06-16 |
2.0.29 | High risk | 51 | 2026-06-12 |
2.0.28 | High risk | 31 | 2026-06-09 |
2.0.27 | High risk | 31 | 2026-05-30 |
2.0.26 | High risk | 31 | 2026-05-30 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi dreadnode==2.0.30