PyPI · pypi.org
frago-cli
Known Indicator Filename: frago_cli-1.0.0/src/frago/chrome/cdp/stealth.js
Why PkgRadar flagged 1.0.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Known Indicator Filename | frago_cli-1.0.0/src/frago/chrome/cdp/stealth.js · frago_cli-1.0.0/src/frago/chrome/cdp/stealth.js |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · frago_cli-1.0.0/src/frago/chrome/backends/extension.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · frago_cli-1.0.0/src/frago/recipes/installer.py |
| medium | Remote Payload | matched "curl " · frago_cli-1.0.0/local_install.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.0 | High risk | 74 | 2026-06-04 |
Block this in CI
pkgradar gate --ecosystem pypi frago-cli==1.0.0