PkgRadar

PyPI · pypi.org

medicafe

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.260608.7

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · medicafe-0.260608.7/cloud/orchestrator/setup_flow.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · medicafe-0.260608.7/scripts/unified_model/phase_d_dat_smoke_common.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · medicafe-0.260608.7/scripts/unified_model/phase_d_resolver_store.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · medicafe-0.260608.7/cloud/orchestrator/services.py
mediumCredential file accessmatched "GOOGLE_APPLICATION_CREDENTIALS" · medicafe-0.260608.7/tools/adc_file_check.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.260608.7High risk622026-06-08
0.260608.6High risk622026-06-08
0.260608.5High risk622026-06-08
0.260608.4High risk622026-06-08
0.260608.3High risk622026-06-08
0.260608.2High risk622026-06-08
0.260608.1High risk622026-06-08
0.260608.0High risk622026-06-08
0.260607.5High risk622026-06-07
0.260607.4High risk622026-06-07
0.260607.3High risk622026-06-07
0.260607.2High risk622026-06-07
0.260607.1High risk622026-06-07
0.260607.0High risk622026-06-07
0.260606.4High risk622026-06-06
0.260606.3High risk622026-06-06
0.260606.2High risk622026-06-06
0.260606.1High risk622026-06-06
0.260606.0High risk622026-06-06
0.260605.0High risk622026-06-05
0.260603.4High risk622026-06-03
0.260603.3High risk622026-06-03
0.260603.2High risk622026-06-03
0.260603.1High risk622026-06-03
0.260603.0High risk622026-06-03
0.260602.0High risk622026-06-02
0.260531.0High risk622026-05-31
0.260527.1High risk622026-05-30
0.260527.0High risk622026-05-30

Block this in CI

PkgRadar gates medicafe (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi medicafe==0.260608.7