VDB
Sign up

MAL-2026-15861

Malicious code in py-1requests (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (877b4b612041848c46e9fb32160b85b74e7c3e983a38313017bc8c034e5f93da) During import, the code exfiltrates potentially sensitive env variables. In all analyzed versions the exfiltration target was a localhost, suggesting it was just a test.

---

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2026-09-0requests

Reasons (based on the campaign):

- exfiltration-env-variables

- typosquatting

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/py-1requests

No fixed version published yet for py-1requests (pip). Pin to a known-safe version or switch to an alternative.

References