PkgRadar

PyPI · pypi.org

filedna

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 1.2.6

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · filedna-1.2.6/testenv/Lib/site-packages/PIL/ImageGrab.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · filedna-1.2.6/testenv/Lib/site-packages/pip/_vendor/pkg_resources/__init__.py
mediumPy Import Time Eval ExecPython eval()/exec() called on a string. · filedna-1.2.6/testenv/Lib/site-packages/pkg_resources/__init__.py
mediumPy Import Time Ctypes Loadctypes.CDLL/cdll.LoadLibrary — loads native code into the process. · filedna-1.2.6/testenv/Lib/site-packages/pypdfium2_raw/__init__.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.6High risk1272026-06-11
1.2.4Low risk02026-06-11

Block this in CI

PkgRadar gates filedna (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi filedna==1.2.6