PkgRadar

PyPI · pypi.org

ojhunt

Remote Payload: matched "curl "

Why PkgRadar flagged 2026.6.1.175045

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · ojhunt-2026.6.1.175045/doit.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.9.62334Low risk02026-06-09
2026.6.7.161534Low risk02026-06-07
2026.6.7.161528Low risk02026-06-07
2026.6.7.161424Low risk02026-06-07
2026.6.7.161345Low risk02026-06-07
2026.6.7.161401Low risk02026-06-07
2026.6.4.912Low risk02026-06-04
2026.6.2.13016Low risk02026-06-02
2026.6.1.182700Low risk02026-06-01
2026.6.1.175045Review122026-06-01
2026.6.1.172017Review122026-06-01
2026.6.1.170338Review122026-06-01
2026.5.31.161954Review122026-05-31
2026.5.31.161920Review122026-05-31

Block this in CI

PkgRadar gates ojhunt (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi ojhunt==2026.6.1.175045