PyPI · pypi.org
letta-nightly
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 0.16.8.dev20260613112240
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · letta_nightly-0.16.8.dev20260613112240/letta/services/tool_executor/tool_execution_sandbox.py |
| medium | Remote Payload | matched "github.com/open-telemetry/opentelemetry-collector-releases/releases/download" · letta_nightly-0.16.8.dev20260613112240/otel/start-otel-collector.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.16.8.dev20260613112240 | High risk | 31 | 2026-06-13 |
0.16.8.dev20260612115025 | High risk | 31 | 2026-06-12 |
0.16.8.dev20260611115932 | High risk | 31 | 2026-06-11 |
0.16.8.dev20260610114728 | High risk | 31 | 2026-06-10 |
0.16.8.dev20260609113957 | High risk | 31 | 2026-06-09 |
0.16.8.dev20260608121206 | High risk | 31 | 2026-06-08 |
0.16.8.dev20260607111628 | High risk | 31 | 2026-06-07 |
0.16.8.dev20260606110624 | High risk | 31 | 2026-06-06 |
0.16.8.dev20260605114054 | High risk | 31 | 2026-06-05 |
0.16.8.dev20260604113611 | High risk | 31 | 2026-06-04 |
0.16.8.dev20260603121421 | High risk | 31 | 2026-06-03 |
0.16.8.dev20260602115710 | High risk | 31 | 2026-06-02 |
0.16.8.dev20260601122724 | High risk | 31 | 2026-06-01 |
0.16.8.dev20260531111227 | High risk | 31 | 2026-05-31 |
0.16.8.dev20260530110441 | High risk | 31 | 2026-05-30 |
0.16.8.dev20260529114250 | High risk | 31 | 2026-05-30 |
0.16.8.dev20260528114914 | High risk | 31 | 2026-05-30 |
0.16.8.dev20260527114924 | High risk | 31 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi letta-nightly==0.16.8.dev20260613112240