PkgRadar

PyPI · pypi.org

entroly

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 1.0.24

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · entroly-1.0.24/entroly/dashboard.py
mediumRemote Payloadmatched "api.telegram.org/bot" · entroly-1.0.24/entroly-wasm/js/gateways.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.24High risk522026-06-11
1.0.23High risk522026-06-10
1.0.22High risk522026-06-08
1.0.20High risk522026-06-07
1.0.19High risk522026-06-07
1.0.18High risk522026-06-06
1.0.17High risk522026-06-05
1.0.16High risk522026-06-05
1.0.15High risk522026-06-04
1.0.14High risk522026-06-03
1.0.13High risk522026-06-01
1.0.11High risk522026-05-30
1.0.9High risk522026-05-30
1.0.8High risk522026-05-30
1.0.7High risk522026-05-30

Block this in CI

PkgRadar gates entroly (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi entroly==1.0.24