py-2equests@0.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC
OSV ID
MAL-2026-15862
Ecosystem
pypi
Summary
py-2equests is a typosquat of the popular 'requests' package (substituting '2' for 'r'). On import py_2equests, the top-level module body iterates os.environ and collects all variables whose keys start with SECRET, API, TOKEN, or KEY, then opens a TCP socket to a host/port taken from the TS_HOST/TS_PORT environment variables (defaulting to 127.0.0.1:9999 but overridable to any remote destination) and sends the collected secrets over it. The same import path then spawns a python subprocess that connects back to the same TS_HOST:TS_PORT, sends the literal 'SHELL', and holds the socket open as a reverse-shell channel, described in an author comment as a 'reverse shell hook'. A code comment reads 'Exfiltrate env vars and open reverse shell on install' and the CLI prints 'py_2equests installed -- targeting requests', self-documenting the intent. Any process that imports the package leaks credential-shaped environment variables and grants remote shell access to whoever controls the configured destination.
Source: amazon-inspector (9bd7b93cf88d0fbcca30c50d9c9de6e14134cd2890be5a7a785e9330e98a988c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.