pypi · Malicious package advisory
Malwarepy-1requests
GHSA-q75m-3rvx-hjp9
Malicious code in py-1requests (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 0.0.1` ## Source: kam193 (877b4b612041848c46e9fb32160b85b74e7c3e983a38313017bc8c034e5f93da) During import, the code exfiltrates potentially sensitive env variables. In all analyzed versions the exfiltration target was a localhost, suggesting it was just a test. --- Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities. Campaign: 2026-09-0requests Reasons (based on the campaign): - exfiltration-env-variables - typosquatting --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/cb149cfb891cf295dcabd697696e9ad6de09603f/osv/malicious/pypi/py-1requests/MAL-2026-15861.json)) **References:** - https://bad-packages.kam193.eu/pypi/package/py-1requests - https://github.com/ossf/malicious-packages/blob/cb149cfb891cf295dcabd697696e9ad6de09603f/osv/malicious/pypi/py-1requests/MAL-2026-15861.json - https://github.com/ossf/malicious-packages/blob/b2e6cd8bd1819c59f7afadfef27650fd124f3de2/osv/malicious/pypi/py-1requests/MAL-2026-15861.json - https://pypi.org/project/py-1requests/0.0.1 - https://github.com/advisories/GHSA-q75m-3rvx-hjp9
Compromised versions (1)
- = 0.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.