PkgRadar

PyPI · pypi.org

structurefinder

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 93

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · structurefinder-93/src/structurefinder/cgi_ui/bottle.py

Scanned versions

VersionVerdictScoreScanned (UTC)
93High risk152026-06-04
92High risk152026-06-01

Block this in CI

PkgRadar gates structurefinder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi structurefinder==93