PkgRadar

Package evidence

lisflood-utilities==1.0.2

Py Install Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
54Mature · −50% score
First published
Aug 2019
Publisher
Valerio Lorini, Stefania Grimaldi, Carlo Russo, Goncalo Gomes, Domenico Nappo, Lorenzo Alfieri, Jesús Casado Rodríguez, Giuseppe Baiamonte, Corentin Carton de Wiart, Cinzia Mazzetti, Nikolaos Mastrantonas

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["lisflood-utilities==1.0.2"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["lisflood-utilities==1.0.2"],"fail_on":"high"}'
Artifact bytes220,992
Previous versionnone
Published2026-06-10T12:58:34
SHA-2560fdf8bfa0c4c05b4bcd6036fa00f1f6e100a66c3acd8e08a23671362a8f4f737

Why flagged

What the scanner saw

Py Install Time Os System: Direct shell invocation via os.system / os.popen / os.exec*.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
50Score
1.0.2Version
Status history (1 event)
  1. newavailable · risk high · score 50 · status changed

Evidence

Static findings

3 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highPy Install Time Os Systemlisflood_utilities-1.0.2/setup.pyDirect shell invocation via os.system / os.popen / os.exec*.105
mediumPy Install Time Subprocesslisflood_utilities-1.0.2/setup.pysubprocess call — process spawning.60
Show all 3 findings (low-signal and informational)
SeverityKindPathDetailPoints
highPy Install Time Os Systemlisflood_utilities-1.0.2/setup.pyDirect shell invocation via os.system / os.popen / os.exec*.105
mediumPy Install Time Subprocesslisflood_utilities-1.0.2/setup.pysubprocess call — process spawning.60
lowSdist Has Setup PymanifestSource distribution executes setup.py at install time.0