PyPI · pypi.org
nvflare
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 2.8.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · nvflare/app_opt/confidential_computing/snp_authorizer.py |
| high | DNS / OAST exfiltration | matched "dig and jq. Now checking if they are installed.\"\n\n check_binary aws \"Please see https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html on how to install it on your system.\"\n check_binary sshpass \"Please install it first.\"\n check_binary dig \"Please install it first.\"\n check_binary jq \"Please install it first.\"\n\n REGION=$(aws configure get region 2>/dev/null)\n : \"${REGION:=us-west-2}\"\n : \"${AWS_DEFAULT_REGION:=$REGION}\"\n : \"${AWS_REGION:=$AWS_DEFAULT_REGION}\"\n REGION=${AWS_REGION}\n\n echo \"Note: run this command first for a different AWS profile:\"\n echo \" export AWS_PROFILE=your-profile-name.\"\n\n echo -e \"\\nChecking AWS identity ... \\n\"\n aws_identity=$(" · nvflare/lighter/templates/aws_template.yml |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.8.0 | Review | 18 | 2026-06-04 |
2.8.0rc7 | Review | 18 | 2026-06-03 |
2.8.0rc6 | Review | 18 | 2026-06-02 |
2.8.0rc5 | Review | 18 | 2026-05-29 |
2.8.0rc4 | Review | 18 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem pypi nvflare==2.8.0