Malicious code in reguestsc (PyPI)
A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count of malicious package versions
- Ecosystems
- Attack vectors
- Affected entities
- reguestscMalicious package on PyPI; typosquat of legitimate library
A malicious package named reguestsc was discovered on PyPI, identified as a typosquat campaign targeting users of a legitimate library. The package cloned the legitimate library's code but injected malicious functionality.
Upon import, the compromised package downloads and executes a remote executable. Dynamic analysis identified the payload as salatstealer, an infostealer malware designed to exfiltrate sensitive information from infected systems.
The campaign was cataloged as 2026-07-reguestsc and credited to the OpenSSF's malicious-packages repository. The malicious intent is clear: the injected code performs spyware-like behavior characteristic of information-stealing malware.
Indicators of compromise
- Packages
- reguestsc
Remediation
- Remove reguestsc from all environments and dependency lists
- Audit systems that imported reguestsc for signs of compromise or data exfiltration
- Use the legitimate package name instead of reguestsc
- Monitor for similar typosquat packages targeting the legitimate library
- Review PyPI package names carefully before installation to avoid typosquats
Sources
- GitHub Advisory GHSA-fg2c-58m3-mg4m · GitHub Advisory Database
Cite this entry
"Malicious code in reguestsc (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-reguestsc-pypi-1rqerl
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in yelp-pkg (PyPI)
yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.
PyPICompromised packageTyposquatting - containedcritical
Malicious code in yt-api-dlp (PyPI)
yt-api-dlp, a typosquat of the legitimate yt-dlp package on PyPI, contains malicious code that downloads encrypted payloads and communicates with a C2 server via the Polygon blockchain during import. The package was a near-verbatim copy of yt-dlp with added malicious functionality.
PyPITyposquattingCompromised package - resolvedcritical
Malicious code in ypthon-binance (PyPI)
Over 900 malicious packages were distributed via PyPI, including ypthon-binance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in zero123 (PyPI)
Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.
PyPICompromised packageTyposquatting