PkgRadar

Package evidence

wisent-tools==0.1.86

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
83
First published
Apr 2026
Publisher
Lukasz Bartoszcze and the Wisent Team

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["wisent-tools==0.1.86"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["wisent-tools==0.1.86"],"fail_on":"high"}'
Artifact bytes71,038
Previous versionnone
Published2026-06-11T16:25:07
SHA-25686b1f1652c525a11daea0ca2ced1d4cdf95f0a9b5e994301ea52b824ef47278d

Why flagged

What the scanner saw

Py Runtime Base64 Decode: base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
30Score
0.1.86Version
Status history (1 event)
  1. newavailable · risk high · score 30 · status changed

Evidence

Static findings

2 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highPy Runtime Base64 Decodewisent_tools-0.1.86/wisent/scripts/activations/supabase/pairs.pybase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.30
Show all 2 findings (low-signal and informational)
SeverityKindPathDetailPoints
highPy Runtime Base64 Decodewisent_tools-0.1.86/wisent/scripts/activations/supabase/pairs.pybase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern.30
lowSdist Has Setup PymanifestSource distribution executes setup.py at install time.0