PkgRadar

PyPI · pypi.org

mcli-framework

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 8.0.58

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · mcli_framework-8.0.58/src/mcli/app/new_cmd.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · mcli_framework-8.0.58/src/mcli/lib/script_loader.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · mcli_framework-8.0.58/src/mcli/lib/script_sync.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · mcli_framework-8.0.58/src/mcli/lib/auth/token_util.py

Scanned versions

VersionVerdictScoreScanned (UTC)
8.0.58High risk562026-06-11
8.0.57High risk562026-06-11
8.0.56High risk212026-06-02
8.0.55High risk212026-06-01
8.0.54High risk212026-06-01
8.0.53High risk212026-06-01
8.0.51High risk212026-05-30
8.0.50High risk212026-05-30
8.0.52High risk212026-05-30
8.0.49High risk212026-05-30

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates mcli-framework (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi mcli-framework==8.0.58