PyPI · pypi.org
orchestr8-platform
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 3.3.2
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · orchestr8/cli.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · orchestr8/auth/keycloak_idp.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · orchestr8/commands/argocd.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · orchestr8/core/orchestrator.py |
| medium | Credential file access | matched "GOOGLE_APPLICATION_CREDENTIALS" · orchestr8/commands/secrets.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.3.2 | High risk | 45 | 2026-06-07 |
Block this in CI
pkgradar gate --ecosystem pypi orchestr8-platform==3.3.2