2026 08 Httpz Requests supply chain incidents
2 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.
- resolvedcritical
Malicious code in infogram-bot (PyPI)
The infogram-bot package on PyPI contained deliberately malicious code designed to provide remote access, exfiltrate files and credentials, and establish persistence on affected systems. The package was identified as part of the 2026-08-httpz-requests campaign.
2026 08 Httpz RequestsPyPICompromised package - containedcritical
Malicious code in httpz-requests (PyPI)
The PyPI package httpz-requests contained deliberately injected malicious code providing Telegram-based remote access, file exfiltration, credential theft, and persistence mechanisms. The package was identified as part of a coordinated malicious campaign (2026-08-httpz-requests) by the OpenSSF.
2026 08 Httpz RequestsPyPICompromised package