Malicious code in reguestsc (PyPI)
A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count of malicious package versions
- Ecosystems
- Attack vectors
- Affected entities
- reguestscMalicious package on PyPI; typosquat of legitimate library
A malicious package named reguestsc was discovered on PyPI, identified as a typosquat campaign targeting users of a legitimate library. The package cloned the legitimate library's code but injected malicious functionality.
Upon import, the compromised package downloads and executes a remote executable. Dynamic analysis identified the payload as salatstealer, an infostealer malware designed to exfiltrate sensitive information from infected systems.
The campaign was cataloged as 2026-07-reguestsc and credited to the OpenSSF's malicious-packages repository. The malicious intent is clear: the injected code performs spyware-like behavior characteristic of information-stealing malware.
Indicators of compromise
- Packages
- reguestsc
Remediation
- Remove reguestsc from all environments and dependency lists
- Audit systems that imported reguestsc for signs of compromise or data exfiltration
- Use the legitimate package name instead of reguestsc
- Monitor for similar typosquat packages targeting the legitimate library
- Review PyPI package names carefully before installation to avoid typosquats
Sources
- GitHub Advisory GHSA-fg2c-58m3-mg4m · GitHub Advisory Database
Cite this entry
"Malicious code in reguestsc (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-reguestsc-pypi-1rqerl
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @years19/n8n-nodes-utils-helper-d (npm)
The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.
npmPyPICompromised packageTyposquatting - containedcritical
Malicious code in fast-hashes (PyPI)
A malicious package named fast-hashes was published to PyPI, using typosquatting to imitate a legitimate library. During installation, obfuscated code downloads and executes a remote malicious executable that exfiltrates cryptocurrency wallet data and potentially other sensitive information.
2026 08 Flasq CampaignPyPITyposquattingCompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package