Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in reguestsc (PyPI)

A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation count of malicious package versions
Ecosystems
Attack vectors
Affected entities
  • reguestscMalicious package on PyPI; typosquat of legitimate library

A malicious package named reguestsc was discovered on PyPI, identified as a typosquat campaign targeting users of a legitimate library. The package cloned the legitimate library's code but injected malicious functionality.

Upon import, the compromised package downloads and executes a remote executable. Dynamic analysis identified the payload as salatstealer, an infostealer malware designed to exfiltrate sensitive information from infected systems.

The campaign was cataloged as 2026-07-reguestsc and credited to the OpenSSF's malicious-packages repository. The malicious intent is clear: the injected code performs spyware-like behavior characteristic of information-stealing malware.

Indicators of compromise

Packages
  • reguestsc

Remediation

  • Remove reguestsc from all environments and dependency lists
  • Audit systems that imported reguestsc for signs of compromise or data exfiltration
  • Use the legitimate package name instead of reguestsc
  • Monitor for similar typosquat packages targeting the legitimate library
  • Review PyPI package names carefully before installation to avoid typosquats

Sources

  1. GitHub Advisory GHSA-fg2c-58m3-mg4m · GitHub Advisory Database

Cite this entry

"Malicious code in reguestsc (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-reguestsc-pypi-1rqerl

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

    The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.

    npmPyPICompromised packageTyposquatting
  2. containedcritical

    Malicious code in fast-hashes (PyPI)

    A malicious package named fast-hashes was published to PyPI, using typosquatting to imitate a legitimate library. During installation, obfuscated code downloads and executes a remote malicious executable that exfiltrates cryptocurrency wallet data and potentially other sensitive information.

    2026 08 Flasq CampaignPyPITyposquattingCompromised package
  3. containedcritical

    Malicious code in fastapii (PyPI)

    The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in idnna (PyPI)

    A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package