PyPI · pypi.org
meshagent-cli
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 0.44.11
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · meshagent_cli-0.44.11/meshagent/cli/tui/setup_splash_frames.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · meshagent_cli-0.44.11/meshagent/cli/ask.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.44.11 | High risk | 37 | 2026-06-11 |
0.44.10 | High risk | 17 | 2026-06-07 |
0.44.9 | High risk | 17 | 2026-06-07 |
0.44.8 | High risk | 17 | 2026-06-06 |
0.44.7 | High risk | 17 | 2026-06-06 |
0.44.6 | High risk | 17 | 2026-06-04 |
0.44.5 | High risk | 17 | 2026-06-04 |
0.44.4 | High risk | 17 | 2026-06-04 |
0.44.3 | High risk | 17 | 2026-06-03 |
0.44.2 | High risk | 17 | 2026-06-02 |
0.44.1 | High risk | 17 | 2026-06-02 |
0.44.0 | High risk | 17 | 2026-06-02 |
0.43.3 | High risk | 17 | 2026-05-30 |
0.43.2 | High risk | 17 | 2026-05-30 |
0.43.1 | High risk | 17 | 2026-05-30 |
0.43.0 | High risk | 17 | 2026-05-30 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem pypi meshagent-cli==0.44.11