PkgRadar

PyPI · pypi.org

playmolecule

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 2.6.50

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · playmolecule-2.6.50/playmolecule/_backends/_docker.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.6.50High risk152026-06-12
2.6.49High risk152026-06-12
2.6.48High risk152026-06-11
2.6.47High risk152026-06-10
2.6.45High risk152026-06-09
2.6.44High risk152026-06-08
2.6.43High risk152026-06-04
2.6.42High risk152026-06-03
2.6.41High risk152026-06-01
2.6.40High risk152026-05-30

Block this in CI

PkgRadar gates playmolecule (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi playmolecule==2.6.50