PkgRadar

PyPI · pypi.org

pythontk

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.8.63

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · pythontk/file_utils/mesh_convert/_mesh_convert.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.63High risk152026-06-11
0.8.61High risk152026-06-10
0.8.59High risk152026-06-09
0.8.58High risk152026-06-05
0.8.56High risk152026-06-04
0.8.54High risk152026-06-04

Block this in CI

PkgRadar gates pythontk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi pythontk==0.8.63