Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Httpz Requests supply chain incidents

2 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in infogram-bot (PyPI)

    The infogram-bot package on PyPI contained deliberately malicious code designed to provide remote access, exfiltrate files and credentials, and establish persistence on affected systems. The package was identified as part of the 2026-08-httpz-requests campaign.

    2026 08 Httpz RequestsPyPICompromised package
  2. containedcritical

    Malicious code in httpz-requests (PyPI)

    The PyPI package httpz-requests contained deliberately injected malicious code providing Telegram-based remote access, file exfiltration, credential theft, and persistence mechanisms. The package was identified as part of a coordinated malicious campaign (2026-08-httpz-requests) by the OpenSSF.

    2026 08 Httpz RequestsPyPICompromised package