PkgRadar

PyPI · pypi.org

opencomputer

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 2026.6.5

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · opencomputer/service/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · opencomputer/commands/ui/clipboard.py
highCredential file accessmatched ".ssh/" · opencomputer/security/python_safety.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · opencomputer/skills/_archive/google-workspace/scripts/google_api.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.5High risk1622026-06-03
2026.6.4High risk1622026-06-01
2026.6.3High risk1622026-06-01
2026.6.2High risk1622026-06-01
2026.6.1High risk1622026-06-01
2026.5.50High risk1622026-05-30
2026.5.49High risk1622026-05-30
2026.5.48High risk1622026-05-30
2026.5.27High risk1622026-05-30
2026.5.47High risk1622026-05-30
2026.5.46High risk1622026-05-30
2026.5.45High risk1622026-05-30
2026.5.44High risk1622026-05-30
2026.5.43High risk1622026-05-30
2026.5.42High risk1622026-05-30
2026.5.41High risk1622026-05-30
2026.5.40High risk1622026-05-30
2026.5.39High risk1622026-05-30
2026.5.38High risk1622026-05-30
2026.5.37High risk1622026-05-30
2026.5.36High risk1622026-05-30
2026.5.35High risk1622026-05-30
2026.5.34High risk1622026-05-30
2026.5.33High risk1622026-05-30
2026.5.32High risk1622026-05-30
2026.5.31High risk1622026-05-30
2026.5.30High risk1622026-05-30
2026.5.29High risk1622026-05-30
2026.5.28High risk1622026-05-30

Block this in CI

PkgRadar gates opencomputer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi opencomputer==2026.6.5