PyPI · pypi.org
ratio1
Webhook Exfil Endpoint: matched "ngrok.app"
Why PkgRadar flagged 3.5.43
| Severity | Signal | Evidence |
|---|---|---|
| high | Webhook Exfil Endpoint | matched "ngrok.app" · ratio1-3.5.43/xperimental/_checks/cstore_check.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ratio1-3.5.43/ratio1/code_cheker/base.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · ratio1-3.5.43/ratio1/ipfs/r1fs.py |
| medium | Remote Payload | matched "wget " · ratio1-3.5.43/ratio1/ipfs/ipfs_setup/setup.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.5.43 | High risk | 51 | 2026-06-05 |
3.5.42 | High risk | 51 | 2026-06-05 |
Block this in CI
pkgradar gate --ecosystem pypi ratio1==3.5.43