PkgRadar

PyPI · pypi.org

openbrowser-ai

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.1.45

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · openbrowser_ai-0.1.45/src/openbrowser/browser/video_recorder.py
mediumRemote Payloadmatched "curl " · openbrowser_ai-0.1.45/install.sh
mediumRemote Payloadmatched "curl " · openbrowser_ai-0.1.45/infra/eval/terraform/user_data.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.45High risk642026-06-02
0.1.44High risk642026-06-02
0.1.43High risk642026-06-02

Block this in CI

PkgRadar gates openbrowser-ai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi openbrowser-ai==0.1.45