Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in reguestsc (PyPI)

A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation count of malicious package versions
Ecosystems
Attack vectors
Affected entities
  • reguestscMalicious package on PyPI; typosquat of legitimate library

A malicious package named reguestsc was discovered on PyPI, identified as a typosquat campaign targeting users of a legitimate library. The package cloned the legitimate library's code but injected malicious functionality.

Upon import, the compromised package downloads and executes a remote executable. Dynamic analysis identified the payload as salatstealer, an infostealer malware designed to exfiltrate sensitive information from infected systems.

The campaign was cataloged as 2026-07-reguestsc and credited to the OpenSSF's malicious-packages repository. The malicious intent is clear: the injected code performs spyware-like behavior characteristic of information-stealing malware.

Indicators of compromise

Packages
  • reguestsc

Remediation

  • Remove reguestsc from all environments and dependency lists
  • Audit systems that imported reguestsc for signs of compromise or data exfiltration
  • Use the legitimate package name instead of reguestsc
  • Monitor for similar typosquat packages targeting the legitimate library
  • Review PyPI package names carefully before installation to avoid typosquats

Sources

  1. GitHub Advisory GHSA-fg2c-58m3-mg4m · GitHub Advisory Database

Cite this entry

"Malicious code in reguestsc (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-reguestsc-pypi-1rqerl

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in yelp-pkg (PyPI)

    yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.

    PyPICompromised packageTyposquatting
  2. containedcritical

    Malicious code in yt-api-dlp (PyPI)

    yt-api-dlp, a typosquat of the legitimate yt-dlp package on PyPI, contains malicious code that downloads encrypted payloads and communicates with a C2 server via the Polygon blockchain during import. The package was a near-verbatim copy of yt-dlp with added malicious functionality.

    PyPITyposquattingCompromised package
  3. resolvedcritical

    Malicious code in ypthon-binance (PyPI)

    Over 900 malicious packages were distributed via PyPI, including ypthon-binance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised packageTyposquatting
  4. resolvedhigh

    Malicious code in zero123 (PyPI)

    Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.

    PyPICompromised packageTyposquatting