PkgRadar

PyPI · pypi.org

salt

Py Install Time Subprocess: subprocess call — process spawning.

Why PkgRadar flagged 3008.1

SeveritySignalEvidence
mediumPy Install Time Subprocesssubprocess call — process spawning. · salt-3008.1/setup.py
highPy Install Time Network CallNetwork call (urllib/requests/httpx/http.client) at install or import time. · salt-3008.1/setup.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · salt-3008.1/salt/client/ssh/__init__.py
mediumPy Import Time Subprocesssubprocess call — process spawning. · salt-3008.1/salt/utils/decorators/__init__.py
highPy Runtime Base64 Decodebase64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · salt-3008.1/salt/modules/ssh.py
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `salt_build_backend` — runs custom code at install time. · pyproject.toml
mediumRemote Payloadmatched "wget " · salt-3008.1/salt/cloud/deploy/Debian-git.sh
mediumRemote Payloadmatched "wget " · salt-3008.1/salt/cloud/deploy/Debian.sh
mediumRemote Payloadmatched "wget " · salt-3008.1/salt/cloud/deploy/SmartOS.sh
mediumRemote Payloadmatched "wget " · salt-3008.1/salt/cloud/deploy/Ubuntu-git.sh
mediumRemote Payloadmatched "wget " · salt-3008.1/salt/cloud/deploy/Ubuntu.sh
mediumRemote Payloadmatched "curl " · salt-3008.1/salt/cloud/deploy/curl-bootstrap-git.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
3008.1Review872026-06-11
3008.0Review1232026-05-27

Block this in CI

PkgRadar gates salt (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi salt==3008.1