PkgRadar

PyPI · pypi.org

marin-finelog

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.2.8.dev202606050858

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · marin_finelog-0.2.8.dev202606050858/dashboard/scripts/demo.py
mediumRemote Payloadmatched "curl " · marin_finelog-0.2.8.dev202606050858/src/finelog/deploy/_gcp.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.10.dev202606130855Review122026-06-13
0.2.10.dev202606111019Review122026-06-11
0.2.10.dev202606090939Review122026-06-09
0.2.10.dev202606081049Review122026-06-08
0.2.10.dev202606070853Review122026-06-07
0.2.9Review122026-06-05
0.2.8.dev202606050858High risk422026-06-05
0.2.7.dev202606040937High risk422026-06-04
0.2.6.dev202606031026High risk422026-06-03
0.2.5.dev202606020954High risk422026-06-02
0.2.4.dev202606011101High risk422026-06-01
0.2.3.dev202605310830High risk422026-05-31
0.2.2.dev202605300811High risk422026-05-30
0.2.1.dev202605292307High risk422026-05-30

Block this in CI

PkgRadar gates marin-finelog (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi marin-finelog==0.2.8.dev202606050858