PyPI · pypi.org
simba-uw-tf-dev
Credential File Packaged: simba_uw_tf_dev-5.3.8/simba/assets/.env
Why PkgRadar flagged 5.3.8
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential File Packaged | simba_uw_tf_dev-5.3.8/simba/assets/.env · simba_uw_tf_dev-5.3.8/simba/assets/.env |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · simba_uw_tf_dev-5.3.8/simba/utils/read_write.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
5.3.8 | Review | 19 | 2026-06-05 |
Block this in CI
pkgradar gate --ecosystem pypi simba-uw-tf-dev==5.3.8