Logo
pypi

0requests@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-15859

Ecosystem

pypi

Summary

The package name '0requests' is a one-character variant of the popular PyPI package 'requests'. On import of the top-level package, __init__.py enumerates os.environ and collects every variable whose name begins with SECRET, API, TOKEN, or KEY, then opens a TCP socket to a host/port taken from the TS_HOST and TS_PORT environment variables and sends the serialized dictionary of credential-shaped variables. The same import path spawns a python subprocess that connects to the same TS_HOST:TS_PORT, sends a 'SHELL' marker, and sleeps to keep the socket open, providing a remote-controlled shell channel on the host. Console output includes '0requests installed -- targeting requests' and a '[typosquat] exfiltrating' log line, confirming intent.

Source: amazon-inspector (ce3a594da2523b6481bd4639f5d3aaed9ec11a9adf92c2b99bf99d0ab6fb5b78)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.