PyPI · pypi.org
turnstone
Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.
Why PkgRadar flagged 1.6.8
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · turnstone-1.6.8/turnstone/core/session.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.6.8 | High risk | 55 | 2026-06-17 |
1.7.0a2 | High risk | 55 | 2026-06-16 |
1.6.7 | High risk | 55 | 2026-06-16 |
1.6.5 | High risk | 55 | 2026-06-15 |
1.6.4 | High risk | 55 | 2026-06-13 |
1.6.3 | High risk | 55 | 2026-06-12 |
1.6.2 | High risk | 55 | 2026-06-12 |
1.6.1 | High risk | 55 | 2026-06-11 |
1.7.0a1 | High risk | 55 | 2026-06-11 |
1.6.0 | High risk | 55 | 2026-06-11 |
1.6.0rc2 | High risk | 55 | 2026-06-10 |
1.6.0rc1 | High risk | 55 | 2026-06-09 |
1.6.0a12 | High risk | 55 | 2026-06-08 |
1.6.0a11 | High risk | 55 | 2026-06-05 |
1.6.0a10 | Review | 25 | 2026-06-02 |
1.6.0a9 | Review | 20 | 2026-06-01 |
1.6.0a8 | Review | 20 | 2026-05-31 |
1.6.0a7 | Review | 20 | 2026-05-30 |
1.6.0a6 | Review | 25 | 2026-05-29 |
Block this in CI
pkgradar gate --ecosystem pypi turnstone==1.6.8