PkgRadar

PyPI · pypi.org

matrice-compute

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.1.123

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · matrice_compute/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · matrice_compute/instance_utils.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · matrice_compute/scaling.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.123High risk572026-06-13
0.1.122High risk572026-06-08
0.1.121High risk572026-06-04
0.1.120High risk572026-06-03
0.1.114High risk922026-06-03
0.1.113High risk572026-06-02
0.1.112High risk572026-06-02
0.1.111High risk572026-06-02
0.1.110High risk572026-06-02
0.1.109High risk572026-06-02
0.1.108High risk572026-06-02
0.1.107High risk572026-06-02
0.1.106High risk572026-06-02
0.1.105High risk572026-06-02
0.1.104High risk572026-06-01
0.1.103High risk572026-06-01
0.1.102High risk572026-05-31
0.1.101High risk572026-05-30
0.1.100High risk572026-05-30
0.1.99High risk572026-05-30
0.1.98High risk572026-05-30
0.1.97High risk572026-05-30
0.1.96High risk572026-05-30
0.1.95High risk572026-05-30
0.1.94High risk572026-05-30

Block this in CI

PkgRadar gates matrice-compute (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi matrice-compute==0.1.123