PkgRadar

PyPI · pypi.org

smartmemory

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 1.4.33

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · smartmemory-1.4.33/smartmemory_app/setup.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · smartmemory-1.4.33/scripts/generate_seed_patterns.py
highPy Install Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · smartmemory-1.4.33/smartmemory_app/setup.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.33High risk882026-06-17
1.4.32High risk882026-06-13
1.4.28High risk602026-06-08
1.4.27High risk602026-06-07
1.4.26High risk602026-06-06
1.4.25High risk602026-06-05
1.4.24High risk602026-06-05
1.4.6High risk602026-05-30

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates smartmemory (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi smartmemory==1.4.33