PyPI · pypi.org
ork-build
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 0.0.303.dev18
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ork_build-0.0.303.dev18/modules/docker/cicd/ci_impl/_masterimpl.py |
| medium | Remote Payload | matched "curl " · ork_build-0.0.303.dev18/bin_pub/obt.ix.installdeps.ubuntu_x86_64.py |
| medium | Remote Payload | matched "wget " · ork_build-0.0.303.dev18/modules/docker/ps1dev/fetch.sh |
| medium | Credential file access | matched ".ssh/" · ork_build-0.0.303.dev18/modules/docker/cicd/bin/test_worker_android.py |
| medium | Credential file access | matched ".ssh/" · ork_build-0.0.303.dev18/modules/docker/cicd/bin/test_worker_ub20.py |
| medium | Credential file access | matched ".ssh/" · ork_build-0.0.303.dev18/modules/docker/cicd/bin/test_worker_ub22.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.0.303.dev18 | High risk | 47 | 2026-06-12 |
0.0.303.dev17 | High risk | 47 | 2026-06-12 |
0.0.303.dev16 | High risk | 47 | 2026-06-12 |
0.0.303.dev15 | High risk | 47 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi ork-build==0.0.303.dev18