MAL-2026-15859
Malicious code in 0requests (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (b42d4eed37375dfa065db35c2e08365b9557b442c935e645b3e82564c4c32d7c) During import, the code exfiltrates potentially sensitive env variables. In all analyzed versions the exfiltration target was a localhost, suggesting it was just a test.
---
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2026-09-0requests
Reasons (based on the campaign):
- exfiltration-env-variables
- typosquatting
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for 0requests (pip). Pin to a known-safe version or switch to an alternative.