PkgRadar

PyPI · pypi.org

oci-cli

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 3.87.0

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · oci-cli-3.87.0/src/oci_cli/cli_setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.87.0Review92026-06-16
3.86.0Review92026-06-09
3.85.0Review92026-06-02
3.84.0Review822026-05-26

Block this in CI

PkgRadar gates oci-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi oci-cli==3.87.0