PkgRadar

PyPI · pypi.org

orca-openstackclient

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 2.6.1

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · orca_openstackclient-2.6.1/orca_cli/commands/server.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.6.1High risk402026-05-30
2.7.0High risk402026-05-30
2.6.0High risk402026-05-30
2.5.3High risk402026-05-30
2.5.2High risk402026-05-30
2.5.1High risk402026-05-30
2.5.0High risk402026-05-30

Block this in CI

PkgRadar gates orca-openstackclient (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi orca-openstackclient==2.6.1