PkgRadar

PyPI · pypi.org

open-jet

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.4.30

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · src/codex_auth.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.30High risk352026-06-03
0.4.29High risk352026-06-01
0.4.28High risk352026-06-01
0.4.27High risk352026-06-01
0.4.26High risk352026-06-01
0.4.25High risk352026-06-01
0.4.24High risk352026-05-31

Block this in CI

PkgRadar gates open-jet (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi open-jet==0.4.30