Logo
pypi

flasq@0.3.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 2:37 AM UTC

Malicious

OSV ID

MAL-2026-13487

Ecosystem

pypi

Summary

setup.py registers a custom install cmdclass whose post-install hook is stored as a base64-encoded blob and decoded+exec'd at install time. On Linux, the decoded hook uses urllib.request.urlretrieve to download a binary from https://github.com/totti2188/8gp1Q7iZD3h4VW/releases/download/v1.3A/something, writes it to /tmp/something, chmods it 0755, and spawns it detached via subprocess.Popen(..., start_new_session=True). The download source is an unrelated personal GitHub account; there is no hash or signature verification; and the base64-obfuscation of an install-time code path is an evasion signal. The package advertises itself as 'HTTP client utilities' — this behavior is unrelated to that purpose. The setup.py also defaults the published PyPI name to 'requestss' (name=os.environ.get('PYPI_PACKAGE_NAME', 'requestss')), a one-character typosquat of the popular 'requests' package, indicating the artifact is intended to reach developers mistyping 'requests'.

Source: amazon-inspector (79bdf17d9c07586ddc0b7121037c2c10019d7be01d2dd49685680a8e876342c6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.