PkgRadar

PyPI · pypi.org

turnstone

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 1.6.8

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · turnstone-1.6.8/turnstone/core/session.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.8High risk552026-06-17
1.7.0a2High risk552026-06-16
1.6.7High risk552026-06-16
1.6.5High risk552026-06-15
1.6.4High risk552026-06-13
1.6.3High risk552026-06-12
1.6.2High risk552026-06-12
1.6.1High risk552026-06-11
1.7.0a1High risk552026-06-11
1.6.0High risk552026-06-11
1.6.0rc2High risk552026-06-10
1.6.0rc1High risk552026-06-09
1.6.0a12High risk552026-06-08
1.6.0a11High risk552026-06-05
1.6.0a10Review252026-06-02
1.6.0a9Review202026-06-01
1.6.0a8Review202026-05-31
1.6.0a7Review202026-05-30
1.6.0a6Review252026-05-29

Block this in CI

PkgRadar gates turnstone (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi turnstone==1.6.8