PkgRadar

PyPI · pypi.org

immunity-agent

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 1.7.1

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/cli.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/hardener.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/ioc.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/ecosystems/detector.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/ecosystems/metadata.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/scoring/osv_lookup.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/scoring/safe_version.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/supplychain/scoring/typosquat.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · immunity_agent-1.7.1/warden/learning.py
highWebhook Exfil Endpointmatched "webhook.site" · immunity_agent-1.7.1/warden/setup_wizard.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · immunity_agent-1.7.1/warden/audit.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · immunity_agent-1.7.1/warden/setup_wizard.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.1High risk1862026-06-17
1.7.0High risk1862026-06-16
1.6.1High risk1362026-06-08
1.6.0High risk1362026-06-08
1.5.8High risk1362026-06-02
1.5.7High risk1362026-05-31
1.5.5High risk1362026-05-30
1.5.4High risk1362026-05-30
1.5.3High risk1362026-05-30
1.5.1High risk462026-05-30
1.5.0High risk462026-05-30

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates immunity-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi immunity-agent==1.7.1