PkgRadar

PyPI · pypi.org

gradio

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 6.18.0

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · gradio-6.18.0/gradio/templates/frontend/assets/ApiDocs-2l_GcwlZ.js
highCredential File Packagedgradio-6.18.0/js/.npmrc · gradio-6.18.0/js/.npmrc
highCredential File Packagedgradio-6.18.0/js/_spaces-test/.npmrc · gradio-6.18.0/js/_spaces-test/.npmrc
highCredential File Packagedgradio-6.18.0/js/_website/.npmrc · gradio-6.18.0/js/_website/.npmrc
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · gradio-6.18.0/gradio/processing_utils.py

Scanned versions

VersionVerdictScoreScanned (UTC)
6.18.0Review542026-06-11
6.17.3Review542026-06-07
6.16.0Review542026-06-03
6.15.2Review672026-05-28
6.15.1Review882026-05-27
6.15.0Review882026-05-26

Block this in CI

PkgRadar gates gradio (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi gradio==6.18.0