Logo
pypi

py-0requests@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 3:34 PM UTC

Malicious

OSV ID

MAL-2026-15860

Ecosystem

pypi

Summary

py-0requests is a homoglyph typosquat of the PyPI package requests (letter o replaced with digit 0). On import py_0requests, top-level code in the package's __init__.py scrapes os.environ for keys prefixed with SECRET, API, TOKEN, or KEY and sends the collected dictionary over a TCP socket to a host/port read from TS_HOST/TS_PORT (defaulting to 127.0.0.1:9999). The same import path spawns a Python subprocess that opens a TCP connection to the same destination, sends a SHELL marker, and holds the socket open, providing a reverse-shell handshake to whichever operator controls the destination. The package's CLI banner self-identifies as targeting requests and ships no HTTP-client API.

Source: amazon-inspector (bd1f4c6176eadca0e4a460d4434e9957eb9befa90d85feecd49e4baf7f3abb4b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.