snap-queue@1.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 11:33 AM UTC
OSV ID
MAL-2026-16408
Ecosystem
pypi
Summary
The sdist's setup.py defines a _wus_boot() function that is invoked at module top-level before setup(...), so it runs automatically on pip install snap-queue. The function uses subprocess.Popen to launch pythonw.exe (replacing python.exe in sys.executable) running a sibling file _snapqueue_core.py with creationflags=0x08000000 (CREATE_NO_WINDOW), and wraps the whole call in a blanket try/except: pass. Standard modules are aliased under underscore names (_os, _sys, _sp) to reduce visual prominence. The launched _snapqueue_core.py is undocumented in README and package metadata and is unrelated to the advertised FIFO-queue functionality. The combined shape — install-time execution, deliberate console-window suppression on Windows, error-swallowing, and detachment of the child from the pip process — is a hidden install-time stager that hands control on the installer's machine to undocumented sibling code the moment the package is installed.
Source: amazon-inspector (e0bb29642def9150e89bacf4da4e1a64f7bc972cd145053cbb0feee0baa768f3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.