PkgRadar

PyPI · pypi.org

liblinks-and-nodes

Py Import Time Subprocess: subprocess call with shell=True — passes argv to /bin/sh.

Why PkgRadar flagged 2.8.1

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call with shell=True — passes argv to /bin/sh. · pyutils/__init__.py
highClipboard Crypto Stealclipboard access library paired with cryptocurrency seed/key patterns · links_and_nodes_manager/ProcessesGui.py
mediumPy Import Time Ctypes Loadctypes.CDLL/cdll.LoadLibrary — loads native code into the process. · liblinks_and_nodes/__init__.py
mediumLarge Native Blob7503016 bytes · links_and_nodes/linux-x86_64-3.10/_ln.so

Scanned versions

VersionVerdictScoreScanned (UTC)
2.8.1High risk1322026-06-10

Block this in CI

PkgRadar gates liblinks-and-nodes (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi liblinks-and-nodes==2.8.1