PkgRadar

PyPI · pypi.org

feishu-bridge

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 2026.6.9.4

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · feishu_bridge-2026.6.9.4/feishu_bridge/bg_supervisor.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.9.4High risk302026-06-09
2026.6.9.3High risk302026-06-09
2026.6.9.1High risk302026-06-09
2026.6.9High risk302026-06-09
2026.6.2High risk302026-06-01
2026.6.1.1High risk302026-06-01
2026.6.1High risk302026-05-31
2026.5.31.9High risk302026-05-31
2026.5.31.8High risk302026-05-31
2026.5.31.7High risk302026-05-31
2026.5.31.6High risk302026-05-31
2026.5.31.5High risk302026-05-31
2026.5.31.4High risk302026-05-31
2026.5.31.3High risk302026-05-31
2026.5.31.2High risk302026-05-31
2026.5.31.1High risk302026-05-30
2026.5.31High risk302026-05-30
2026.5.30.4High risk302026-05-30
2026.5.30.3High risk302026-05-30
2026.5.30High risk302026-05-30
2026.5.29.5High risk302026-05-30
2026.5.29.4High risk302026-05-30
2026.5.29.3High risk302026-05-30
2026.5.29.1High risk302026-05-30
2026.5.29.2High risk302026-05-30
2026.5.29High risk302026-05-30
2026.5.28High risk302026-05-30
2026.5.27High risk302026-05-30

Block this in CI

PkgRadar gates feishu-bridge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi feishu-bridge==2026.6.9.4