Logo
pypi

py-1requests@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-15861

Ecosystem

pypi

Summary

py_1requests is a typosquat of the popular requests library (leading 1 inserted inside the name). On import, py_1requests/__init__.py iterates os.environ and collects every variable whose name starts with SECRET, API, TOKEN, or KEY, then opens a TCP socket to HOST:PORT and sends the serialized dict; HOST and PORT default to 127.0.0.1:9999 but are overridable via the TS_HOST and TS_PORT environment variables. The same __init__.py spawns a python subprocess that connects to the same host/port and sends a 'SHELL' marker, holding the connection open — a reverse-shell staging path. cli.py prints 'py_1requests installed -- targeting requests' and __init__.py prints '[typosquat] exfiltrating:...', in-source admissions of purpose. Both behaviors fire unconditionally on import with no documented purpose.

Source: amazon-inspector (bd6d1a5c78d4368dc76a90cc90a68e4264170ed9ef208c8096251798734bb0d6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.