PyPI · pypi.org
medusa-security
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 2026.6.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · medusa_security-2026.6.0/medusa/scanners/trivy_scanner.py |
| high | DNS / OAST exfiltration | matched "burpcollaborator.net" · medusa_security-2026.6.0/medusa/rules/agent_security/exfiltration_agents_2026.yaml |
| medium | Credential file access | matched "id_rsa" · medusa_security-2026.6.0/medusa/scanners/mcp_server_scanner.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2026.6.0 | High risk | 109 | 2026-06-10 |
2026.5.11 | High risk | 77 | 2026-05-30 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi medusa-security==2026.6.0