VYPR

pypi · Malicious package advisory

Malware

requests-lite

MAL-2026-1291

Malicious code in requests-lite (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (d343c918303c251cdef262a6e1cbdff6ae797cf56115a81cfa5449732395b63b)
Clone of a legitimate requests library. The hidden code runs when using the requests functionality and starts a Telegram bot awaiting for remote commands.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-03-old-requests-lite


Reasons (based on the campaign):


 - clones-real-package


 - action-hidden-in-lib-usage


 - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.


 - rat


 - abusing-3rd-api

Compromised versions (4)

  • 2.32.3
  • 2.32.4
  • 2.32.5
  • 2.32.7

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.