PyPI · pypi.org
obfuscation
Py Install Time Eval Exec: Python eval()/exec() called on a string.
Early detection
PkgRadar flagged this 7h before public disclosure
Detected 2026-05-31 · disclosed as MAL-2026-5100 on 2026-05-31
Why PkgRadar flagged 3.23.3
| Severity | Signal | Evidence |
|---|---|---|
| medium | Py Install Time Eval Exec | Python eval()/exec() called on a string. · obfuscation-3.23.3/setup.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.23.3 | Review | 45 | 2026-05-31 |
3.23.2 | Review | 45 | 2026-05-31 |
3.23.0 | Review | 45 | 2026-05-31 |
Block this in CI
pkgradar gate --ecosystem pypi obfuscation==3.23.3