PyPI · pypi.org
envdrift
Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.
Why PkgRadar flagged 10.16.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Js Hidden Powershell | Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · envdrift-10.16.1/envdrift-vscode/src/agentStatus.ts |
| high | Js Hidden Powershell | Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · envdrift-10.16.1/envdrift-vscode/src/encryption.ts |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
10.16.1 | High risk | 38 | 2026-06-12 |
10.16.0 | High risk | 38 | 2026-06-11 |
10.15.1 | High risk | 38 | 2026-06-09 |
10.15.0 | High risk | 38 | 2026-06-09 |
10.14.0 | High risk | 38 | 2026-06-08 |
10.13.9 | High risk | 38 | 2026-06-08 |
10.13.8 | High risk | 38 | 2026-06-08 |
10.13.7 | High risk | 38 | 2026-06-07 |
10.13.6 | High risk | 38 | 2026-06-07 |
10.13.5 | High risk | 55 | 2026-06-05 |
10.13.4 | High risk | 55 | 2026-06-05 |
10.13.3 | High risk | 55 | 2026-06-05 |
10.13.2 | High risk | 55 | 2026-06-05 |
0.1.4 | High risk | 55 | 2026-06-04 |
10.13.0 | High risk | 55 | 2026-06-04 |
10.12.4 | High risk | 55 | 2026-06-03 |
10.12.3 | High risk | 55 | 2026-06-03 |
10.12.2 | High risk | 55 | 2026-06-03 |
10.12.1 | High risk | 55 | 2026-06-03 |
10.12.0 | High risk | 55 | 2026-06-02 |
10.11.3 | High risk | 55 | 2026-05-30 |
10.11.2 | High risk | 55 | 2026-05-30 |
0.1.3 | High risk | 55 | 2026-05-30 |
10.11.1 | High risk | 55 | 2026-05-30 |
10.11.0 | High risk | 55 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi envdrift==10.16.1