MAL-2026-16275
Malicious code in requests-triwes (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (fa01be0759de95b7a1628930718f7b3bf372eff0c777aace419196e327e77078) During installation, package starts a reverse shell.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-requests-triwes
Reasons (based on the campaign):
- The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
- The package overrides the install command in setup.py to execute malicious code during installation.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for requests-triwes (pip). Pin to a known-safe version or switch to an alternative.