0requests@0.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-15859
Ecosystem
pypi
Summary
The package name '0requests' is a one-character variant of the popular PyPI package 'requests'. On import of the top-level package, __init__.py enumerates os.environ and collects every variable whose name begins with SECRET, API, TOKEN, or KEY, then opens a TCP socket to a host/port taken from the TS_HOST and TS_PORT environment variables and sends the serialized dictionary of credential-shaped variables. The same import path spawns a python subprocess that connects to the same TS_HOST:TS_PORT, sends a 'SHELL' marker, and sleeps to keep the socket open, providing a remote-controlled shell channel on the host. Console output includes '0requests installed -- targeting requests' and a '[typosquat] exfiltrating' log line, confirming intent.
Source: amazon-inspector (ce3a594da2523b6481bd4639f5d3aaed9ec11a9adf92c2b99bf99d0ab6fb5b78)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.