PkgRadar

PyPI · pypi.org

plugin-scanner

Clipboard Crypto Steal: clipboard access library paired with cryptocurrency seed/key patterns

Why PkgRadar flagged 2.0.762

SeveritySignalEvidence
highClipboard Crypto Stealclipboard access library paired with cryptocurrency seed/key patterns · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/runtime/false_positive_rules.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/checks/operational_security.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/local_supply_chain.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/shim_probe.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/shims.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/cli/commands_support_interaction.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/cli/commands_support_runtime_policy.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/runtime/mcp_protection.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/runtime/mcp_skill_firewall.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/runtime/package_intent_parser.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/runtime/package_manifest_diff.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · plugin_scanner-2.0.762/src/codex_plugin_scanner/guard/runtime/skill_protection.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.762High risk3602026-06-17
2.0.761High risk3602026-06-17
2.0.760High risk3602026-06-17
2.0.759High risk3602026-06-17
2.0.758High risk3602026-06-16
2.0.757High risk3602026-06-16
2.0.756High risk3602026-06-16
2.0.755High risk3602026-06-16
2.0.754High risk3602026-06-16
2.0.753High risk3602026-06-16
2.0.752High risk3602026-06-16
2.0.751High risk3602026-06-16
2.0.750High risk3102026-06-16
2.0.749High risk3102026-06-16
2.0.748High risk3102026-06-16
2.0.747High risk3102026-06-16
2.0.746High risk3102026-06-16
2.0.745High risk3102026-06-16
2.0.744High risk3102026-06-16
2.0.743High risk3102026-06-16
2.0.742High risk3102026-06-16
2.0.741High risk3102026-06-16
2.0.740High risk3102026-06-16
2.0.739High risk3102026-06-16
2.0.738High risk3102026-06-16
2.0.737High risk3102026-06-16
2.0.736High risk3102026-06-16
2.0.735High risk3102026-06-15
2.0.734High risk3102026-06-15
2.0.733High risk3102026-06-15
2.0.732High risk3102026-06-15
2.0.731High risk3102026-06-15
2.0.730High risk3102026-06-15
2.0.729High risk3102026-06-15
2.0.728High risk3102026-06-15
2.0.727High risk3102026-06-15
2.0.726High risk3102026-06-15
2.0.725High risk3102026-06-15
2.0.724High risk3102026-06-15
2.0.723High risk3102026-06-15
2.0.722High risk3102026-06-15
2.0.721High risk3102026-06-15
2.0.720High risk3102026-06-15
2.0.719High risk3102026-06-15
2.0.718High risk3102026-06-15
2.0.717High risk3102026-06-15
2.0.716High risk3102026-06-15
2.0.715High risk3102026-06-15
2.0.714High risk3102026-06-15
2.0.713High risk3102026-06-15
2.0.712High risk3102026-06-15
2.0.711High risk3102026-06-15
2.0.710High risk3102026-06-15
2.0.709High risk3102026-06-15
2.0.708High risk3102026-06-15
2.0.707High risk3102026-06-15
2.0.706High risk3102026-06-15
2.0.705High risk3102026-06-15
2.0.704High risk3102026-06-15
2.0.703High risk3102026-06-15
2.0.702High risk3102026-06-15
2.0.701High risk3102026-06-15
2.0.700High risk3102026-06-15
2.0.699High risk3102026-06-15
2.0.698High risk3102026-06-15
2.0.697High risk3102026-06-15
2.0.696High risk3102026-06-15
2.0.695High risk3102026-06-14
2.0.694High risk3102026-06-14
2.0.693High risk3102026-06-14
2.0.692High risk3102026-06-14
2.0.691High risk3102026-06-14
2.0.690High risk3102026-06-14
2.0.689High risk3102026-06-14
2.0.688High risk3102026-06-14
2.0.687High risk3102026-06-14
2.0.686High risk3102026-06-14
2.0.685High risk3102026-06-14
2.0.684High risk3102026-06-14
2.0.683High risk3102026-06-14
2.0.682High risk3102026-06-14
2.0.681High risk3102026-06-14
2.0.680High risk3102026-06-14
2.0.679High risk3102026-06-14
2.0.678High risk3102026-06-14
2.0.677High risk3102026-06-14
2.0.676High risk3102026-06-14
2.0.675High risk3102026-06-14
2.0.674High risk3102026-06-14
2.0.673High risk3102026-06-14
2.0.672High risk3102026-06-14
2.0.671High risk3102026-06-14
2.0.670High risk3102026-06-14
2.0.669High risk3102026-06-14
2.0.668High risk3102026-06-14
2.0.667High risk3102026-06-14
2.0.666High risk3102026-06-14
2.0.665High risk3102026-06-13
2.0.664High risk3102026-06-13
2.0.663High risk3102026-06-13
2.0.662High risk3102026-06-13
2.0.661High risk3102026-06-13
2.0.660High risk3102026-06-13
2.0.659High risk3102026-06-13
2.0.658High risk3102026-06-13
2.0.657High risk3102026-06-13
2.0.656High risk3102026-06-13
2.0.655High risk3102026-06-13
2.0.654High risk3102026-06-13
2.0.653High risk3102026-06-13
2.0.652High risk3102026-06-13
2.0.651High risk3102026-06-13
2.0.650High risk3102026-06-13
2.0.649High risk3102026-06-13
2.0.648High risk3102026-06-13
2.0.647High risk3102026-06-13
2.0.646High risk3102026-06-13
2.0.645High risk3102026-06-13
2.0.644High risk3102026-06-13
2.0.643High risk3102026-06-13
2.0.642High risk3102026-06-13
2.0.641High risk3102026-06-13
2.0.640High risk3102026-06-13
2.0.639High risk3102026-06-13
2.0.638High risk3102026-06-12
2.0.637High risk3102026-06-12
2.0.636High risk3102026-06-12
2.0.635High risk3102026-06-12
2.0.634High risk3102026-06-12
2.0.633High risk3102026-06-12
2.0.632High risk3102026-06-12
2.0.631High risk3102026-06-12
2.0.630High risk3102026-06-12
2.0.629High risk3102026-06-12
2.0.628High risk3102026-06-12
2.0.627High risk3102026-06-12
2.0.626High risk3102026-06-12
2.0.625High risk3102026-06-12
2.0.624High risk3102026-06-12
2.0.623High risk3102026-06-12
2.0.622High risk3102026-06-12
2.0.621High risk3102026-06-12
2.0.620High risk3102026-06-12
2.0.619High risk3102026-06-12
2.0.618High risk3102026-06-12
2.0.617High risk3102026-06-12
2.0.616High risk3102026-06-12
2.0.615High risk3102026-06-12
2.0.614High risk3102026-06-12
2.0.613High risk3102026-06-12
2.0.612High risk3102026-06-12
2.0.611High risk3102026-06-12
2.0.610High risk3102026-06-12
2.0.609High risk3102026-06-12
2.0.608High risk3102026-06-12
2.0.607High risk3102026-06-12
2.0.606High risk3102026-06-12
2.0.605High risk3102026-06-12
2.0.604High risk3102026-06-12
2.0.603High risk3102026-06-12
2.0.602High risk3102026-06-11
2.0.601High risk3102026-06-11
2.0.600High risk3102026-06-11
2.0.599High risk3102026-06-11
2.0.598High risk3102026-06-11
2.0.597High risk3102026-06-11
2.0.596High risk3102026-06-11
2.0.595High risk3102026-06-11
2.0.594High risk3102026-06-11
2.0.593High risk3102026-06-11
2.0.592High risk3102026-06-11
2.0.591High risk3102026-06-11
2.0.590High risk3102026-06-11
2.0.589High risk3102026-06-11
2.0.588High risk3102026-06-11
2.0.587High risk3102026-06-11
2.0.586High risk3102026-06-11
2.0.585High risk3102026-06-11
2.0.584High risk3102026-06-11
1.2.25High risk3102026-06-11
1High risk3102026-06-11
2.0.583High risk3102026-06-11
2.0.582High risk3102026-06-11
2.0.581High risk3102026-06-11
2.0.580High risk3102026-06-11
2.0.579High risk3102026-06-11
2.0.578High risk3102026-06-11
2.0.577High risk3102026-06-11
2.0.576High risk3102026-06-10
2.0.575High risk3102026-06-10
2.0.574High risk3102026-06-10
2.0.573High risk3102026-06-10
2.0.572High risk3102026-06-10
2.0.571High risk3102026-06-10
2.0.570High risk3102026-06-10
2.0.569High risk3102026-06-10
2.0.568High risk3102026-06-10
2.0.567High risk3102026-06-10
2.0.566High risk3102026-06-10
2.0.565High risk3102026-06-10

Campaign attribution

Part of the Bittensor clipboard stealer campaign.

Block this in CI

PkgRadar gates plugin-scanner (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi plugin-scanner==2.0.762