PkgRadar

PyPI · pypi.org

scripthut

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.11.12

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · scripthut-0.11.12/src/scripthut/main.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.11.12High risk432026-06-11
0.11.11High risk432026-06-11
0.11.10High risk432026-06-11
0.11.9High risk432026-06-11
0.11.8High risk432026-06-10
0.11.7High risk432026-06-10
0.11.6High risk432026-06-10
0.11.5High risk432026-06-10
0.11.4High risk432026-06-10
0.11.3High risk432026-06-09
0.11.2High risk432026-06-04
0.11.1High risk432026-06-04
0.11.0High risk432026-06-04
0.10.0Review132026-06-04
0.9.1Review132026-06-04
0.9.0Review132026-06-04
0.8.0Review132026-06-04
0.7.1Review132026-06-04
0.7.0Review132026-06-03
0.6.5Review132026-06-03
0.6.4Review132026-06-03
0.6.3Review132026-06-03
0.6.2Review132026-06-03
0.6.1Review132026-06-03
0.6.0Review132026-06-03
0.5.7Review132026-06-03
0.5.6Review132026-06-03
0.5.5Review132026-06-03
0.5.4Review132026-06-03
0.5.3Review132026-06-02

Block this in CI

PkgRadar gates scripthut (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi scripthut==0.11.12