PkgRadar

PyPI · pypi.org

mlrun

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 1.12.0rc12

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · mlrun/utils/helpers.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.12.0rc12Review182026-06-09
1.12.0rc11Review182026-06-07
1.12.0rc10Review182026-06-04
1.12.0rc9Review182026-06-03
1.12.0rc7Review222026-05-28
1.12.0rc6Review362026-05-27
1.10.4rc1Review362026-05-27

Block this in CI

PkgRadar gates mlrun (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi mlrun==1.12.0rc12