VDB
Sign up
—

MAL-2026-17191

Malicious code in requests-cache-utils (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (1655ea47fc7ccd39294203776ee3dcb01a394c40d93e05b7b527700b19de42c8) During installation and importing the module, the code downloads and executes an infostealer.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-requests-cache-utils

Reasons (based on the campaign):

- The package overrides the install command in setup.py to execute malicious code during installation.

- Downloads and executes a remote executable.

- malware

- infostealer

- exfiltration-browser-data

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/requests-cache-utils

No fixed version published yet for requests-cache-utils (pip). Pin to a known-safe version or switch to an alternative.

References