PkgRadar

PyPI · pypi.org

picosentry

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 2.0.13

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · picosentry/sandbox/cli_commands/_common.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · picosentry/scan/rules/worm_propagation.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · picosentry/scan/crypto.py
highCredential file accessmatched ".npmrc" · picosentry/scan/rules/post_install.py
highCredential file accessmatched ".pypirc" · picosentry/scan/rules/pypi_post_install.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · picosentry/watch/server.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.13High risk2102026-06-13
2.0.9High risk1602026-06-06
2.0.7High risk1602026-06-06
2.0.2High risk1602026-06-06
2.0.1High risk1602026-06-06
1.0.1High risk752026-06-01
1.0.0High risk752026-06-01
0.16.0High risk702026-05-30

Block this in CI

PkgRadar gates picosentry (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi picosentry==2.0.13