PkgRadar

PyPI · pypi.org

kagesec

DNS / OAST exfiltration: matched "oast.pro"

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "oast.pro" · kagesec-0.3.0.data/purelib/cli/main.py
highDNS / OAST exfiltrationmatched "oast.pro" · kagesec-0.3.0.data/purelib/scanner/core/config.py
highDNS / OAST exfiltrationmatched "oast.fun" · kagesec-0.3.0.data/purelib/scanner/core/interactsh.py
highDNS / OAST exfiltrationmatched "oast.pro" · kagesec-0.3.0.data/purelib/scanner/modules/log4j_deep.py
highDNS / OAST exfiltrationmatched "oast.pro" · kagesec-0.3.0.data/purelib/scanner/templates/cves/CVE-2021-44228.yaml
highDNS / OAST exfiltrationmatched "oast.pro" · kagesec-0.3.0.data/purelib/scanner/templates/cves/CVE-2021-45046.yaml
mediumRemote Payloadmatched "curl " · kagesec-0.3.0.data/purelib/scanner/modules/ssti.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0High risk1002026-06-05
0.2.9High risk1002026-06-04
0.2.8High risk1002026-06-04
0.2.7High risk1002026-06-02
0.2.6High risk1002026-06-01
0.2.5High risk1002026-06-01
0.2.4High risk1002026-05-31
0.2.3High risk1002026-05-30
0.2.2High risk1002026-05-30
0.2.1High risk1002026-05-30
0.2.0High risk1002026-05-30

Block this in CI

PkgRadar gates kagesec (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi kagesec==0.3.0
kagesec — PyPI security scan | PkgRadar