PyPI · pypi.org
nemo-retriever
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 2026.6.13.dev120
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · nemo_retriever-2026.6.13.dev120/src/nemo_retriever/harness/portal/app.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2026.6.13.dev120 | High risk | 38 | 2026-06-13 |
2026.6.13.dev570 | High risk | 38 | 2026-06-13 |
2026.6.12.dev119 | High risk | 38 | 2026-06-12 |
2026.6.12.dev569 | High risk | 38 | 2026-06-12 |
2026.6.11.dev118 | High risk | 38 | 2026-06-11 |
2026.6.9.dev117 | High risk | 38 | 2026-06-10 |
2026.6.8.dev116 | High risk | 38 | 2026-06-08 |
2026.6.8.dev565 | High risk | 38 | 2026-06-08 |
2026.6.8.dev564 | High risk | 38 | 2026-06-08 |
2026.6.7.dev115 | High risk | 38 | 2026-06-07 |
2026.6.6.dev114 | High risk | 38 | 2026-06-06 |
2026.6.5.dev113 | High risk | 38 | 2026-06-05 |
2026.6.4.dev112 | High risk | 38 | 2026-06-04 |
2026.6.4.dev111 | High risk | 38 | 2026-06-04 |
2026.6.3.dev110 | High risk | 38 | 2026-06-03 |
2026.6.1.dev109 | High risk | 38 | 2026-06-01 |
2026.5.31.dev108 | High risk | 38 | 2026-05-31 |
2026.5.30.dev107 | High risk | 38 | 2026-05-30 |
2026.5.29.dev106 | High risk | 38 | 2026-05-30 |
26.5.0 | High risk | 38 | 2026-05-30 |
26.5rc9 | High risk | 38 | 2026-05-30 |
2026.5.28.dev105 | High risk | 38 | 2026-05-30 |
26.5rc8 | High risk | 38 | 2026-05-30 |
26.5rc7 | High risk | 38 | 2026-05-30 |
2026.5.27.dev104 | High risk | 38 | 2026-05-30 |
26.5rc6 | High risk | 38 | 2026-05-30 |
26.5rc5 | High risk | 38 | 2026-05-30 |
2026.5.26.dev103 | High risk | 38 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi nemo-retriever==2026.6.13.dev120