PkgRadar

PyPI · pypi.org

ellf-cli

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 17.0.4

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ellf_cli-17.0.4/ellf_cli/commands/infra/_helpers.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ellf_cli-17.0.4/ellf_cli/commands/infra/deploy.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ellf_cli-17.0.4/ellf_cli/commands/infra/tls.py

Scanned versions

VersionVerdictScoreScanned (UTC)
17.0.4High risk502026-06-11
14.0.0High risk502026-06-11
13.0.2High risk502026-06-10
13.0.1High risk502026-06-10
13.0.0High risk502026-06-10
12.0.0High risk502026-06-09
11.0.1High risk502026-06-09
10.0.3High risk502026-06-05
10.0.2High risk502026-06-05
10.0.1High risk502026-06-04
10.0.0High risk502026-06-02
7.0.0High risk502026-06-01
6.1.11High risk502026-05-30
6.1.9High risk502026-05-30
6.1.8High risk502026-05-30
6.1.6High risk502026-05-30
6.1.5High risk502026-05-30
6.1.4High risk502026-05-30

Block this in CI

PkgRadar gates ellf-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ellf-cli==17.0.4