PkgRadar

PyPI · pypi.org

openyuanrong-sdk

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.7.51

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · yr/cli/scripts.py
mediumPy Import Time Ctypes Loadctypes.CDLL/cdll.LoadLibrary — loads native code into the process. · yr/__init__.py
mediumLarge Native Blob27897760 bytes · yr/fnruntime.cpython-310-darwin.so
mediumLarge Native Blob27792480 bytes · yr/cpp/lib/libyr-api.so

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.51High risk742026-06-12
0.7.49High risk742026-06-08
0.7.48High risk742026-06-04
0.7.47High risk742026-06-03
0.7.46High risk742026-05-31
0.7.45High risk742026-05-31
0.7.44High risk742026-05-30

Block this in CI

PkgRadar gates openyuanrong-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi openyuanrong-sdk==0.7.51