PkgRadar

PyPI · pypi.org

wisent-tools

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Why PkgRadar flagged 0.1.86

SeveritySignalEvidence
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · wisent_tools-0.1.86/wisent/scripts/activations/supabase/pairs.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.86High risk302026-06-11
0.1.85High risk302026-06-10
0.1.84High risk302026-06-10
0.1.83High risk302026-06-10
0.1.82High risk302026-06-10
0.1.81High risk302026-06-10
0.1.80High risk302026-06-10
0.1.79High risk302026-06-08
0.1.78High risk302026-06-08
0.1.77High risk302026-06-04
0.1.76High risk302026-06-04
0.1.75High risk302026-06-04
0.1.74High risk302026-06-04
0.1.73High risk302026-06-01
0.1.69High risk302026-05-30
0.1.68High risk302026-05-30
0.1.67High risk302026-05-30
0.1.66High risk302026-05-30
0.1.65High risk302026-05-30
0.1.64High risk302026-05-30
0.1.63High risk302026-05-30
0.1.62High risk302026-05-30
0.1.61High risk302026-05-30
0.1.60High risk302026-05-30
0.1.59High risk302026-05-30

Block this in CI

PkgRadar gates wisent-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi wisent-tools==0.1.86