PkgRadar

PyPI · pypi.org

halton-meter

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.5.0

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · halton_meter-0.5.0/halton_meter/setup/_windows.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0High risk352026-06-10
0.4.2High risk352026-06-10
0.4.1High risk352026-06-08
0.4.0High risk352026-06-08
0.3.11Review52026-06-07
0.3.10Review52026-06-07
0.3.9Review52026-06-07
0.3.8Review52026-06-05
0.3.6Review52026-06-02
0.3.5Review52026-06-01
0.3.4Review52026-06-01
0.3.3Review52026-05-31
0.3.2Review52026-05-31
0.3.1Review52026-05-31
0.3.0Review52026-05-29
0.2.17Review52026-05-28
0.2.16Review52026-05-28
0.2.15Review52026-05-28
0.2.13Review52026-05-28
0.2.12Review52026-05-28

Block this in CI

PkgRadar gates halton-meter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi halton-meter==0.5.0