py-1requests@0.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC
OSV ID
MAL-2026-15861
Ecosystem
pypi
Summary
py_1requests is a typosquat of the popular requests library (leading 1 inserted inside the name). On import, py_1requests/__init__.py iterates os.environ and collects every variable whose name starts with SECRET, API, TOKEN, or KEY, then opens a TCP socket to HOST:PORT and sends the serialized dict; HOST and PORT default to 127.0.0.1:9999 but are overridable via the TS_HOST and TS_PORT environment variables. The same __init__.py spawns a python subprocess that connects to the same host/port and sends a 'SHELL' marker, holding the connection open — a reverse-shell staging path. cli.py prints 'py_1requests installed -- targeting requests' and __init__.py prints '[typosquat] exfiltrating:...', in-source admissions of purpose. Both behaviors fire unconditionally on import with no documented purpose.
Source: amazon-inspector (bd6d1a5c78d4368dc76a90cc90a68e4264170ed9ef208c8096251798734bb0d6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.