PkgRadar

PyPI · pypi.org

openclaw-context-pack

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 1.9.27

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · openclaw_context_pack-1.9.27/openclaw_mem/capsule.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.9.27High risk452026-06-12
1.9.24High risk452026-05-30

Block this in CI

PkgRadar gates openclaw-context-pack (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi openclaw-context-pack==1.9.27