PkgRadar

PyPI · pypi.org

toil

Py Import Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 9.5.0

SeveritySignalEvidence
mediumPy Import Time Subprocesssubprocess call — process spawning. · toil-9.5.0/src/toil/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · toil-9.5.0/src/toil/batchSystems/contained_executor.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · toil-9.5.0/src/toil/worker.py
mediumCredential file accessmatched "id_rsa" · toil-9.5.0/setup_gitlab_ssh.py

Scanned versions

VersionVerdictScoreScanned (UTC)
9.5.0Review292026-06-03

Block this in CI

PkgRadar gates toil (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi toil==9.5.0