PkgRadar

PyPI · pypi.org

rp

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.1.1421

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · rp-0.1.1421/rp/libs/spotify_downloader.py
mediumRemote Payloadmatched "curl " · rp-0.1.1421/rp/libs/kitten_tts_server.py
mediumRemote Payloadmatched "CURL " · rp-0.1.1421/rp/libs/supertonic_tts_server.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · rp-0.1.1421/rp/rp_ptpython/completer_old.py
mediumRemote Payloadmatched "curl " · rp-0.1.1421/rp/rp_ptpython/completion_schema.py
mediumRemote Payloadmatched "curl " · rp-0.1.1421/rp/prompt_toolkit/terminal/vt100_output.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · rp-0.1.1421/rp/prompt_toolkit/key_binding/digraphs.py
mediumRemote Payloadmatched "curl " · rp-0.1.1421/rp/prompt_toolkit/styles/utils.py
mediumRemote Payloadmatched "curl " · rp-0.1.1421/rp/prompt_toolkit/styles/defaults.py
mediumRemote Payloadmatched "curl " · rp-0.1.1421/rp/prompt_toolkit/styles/base.py
mediumCredential file accessmatched ".ssh" · rp-0.1.1421/rp/rp_ptpython/completion_schema.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.1421Review372026-05-28
0.1.1420Review372026-05-28
0.1.1419Review372026-05-28
0.1.1417Review372026-05-27
0.1.1416Review372026-05-27

Block this in CI

PkgRadar gates rp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi rp==0.1.1421