PyPI · pypi.org
reflex-vla
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 0.11.2
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · reflex_vla-0.11.2/scripts/modal_zmq_vs_http_ab.py |
| medium | Py Import Time Ctypes Load | ctypes.CDLL/cdll.LoadLibrary — loads native code into the process. · reflex_vla-0.11.2/src/reflex/__init__.py |
| medium | Remote Payload | matched "curl " · reflex_vla-0.11.2/infra/contribution-worker/deploy.sh |
| medium | Remote Payload | matched "curl " · reflex_vla-0.11.2/infra/license-worker/deploy.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.11.2 | High risk | 78 | 2026-05-30 |
0.11.1 | High risk | 78 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi reflex-vla==0.11.2