PkgRadar

PyPI · pypi.org

qualix

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 0.2.0a1

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · qualix-0.2.0a1/src/qualix/commands/setup.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · qualix-0.2.0a1/scripts/feishu_browser_images.py
highPy Runtime Dynamic Dangerous ImportDynamic __import__('sys') — reflection bypass for static checks. · qualix-0.2.0a1/src/qualix/tracking/experiment.py

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.0a1High risk1152026-06-01

Block this in CI

PkgRadar gates qualix (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi qualix==0.2.0a1