MAL-2026-11413
Malicious code in reguestsc (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (20e4ae2ce79408a65e9b4bb348c2d69e20eb6072e3641531e2ec5773f1bbddd6) Clones of a legitimate library with injected code downloading and executing a malicious executable on import. Dynamic analysis identified it as salatstealer.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-reguestsc
Reasons (based on the campaign):
- typosquatting
- Downloads and executes a remote executable.
- malware
- clones-real-package
- spyware-like
- infostealer
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for reguestsc (pip). Pin to a known-safe version or switch to an alternative.
References
- https://www.virustotal.com/gui/file/db86ed61afec83acb523e8b00558ee7641b2ddc388d542dc0ff2922625da013f/detection [EVIDENCE]
- https://tria.ge/260731-kqvw2aff97/behavioral1 [EVIDENCE]
- https://app.any.run/tasks/348751a8-657c-4a3d-bee1-dedae5264036 [EVIDENCE]
- https://bad-packages.kam193.eu/pypi/package/reguestsc [WEB]