Malicious code in reqcrypt-dev (PyPI)
The PyPI package reqcrypt-dev contained malicious code implementing a hidden backdoor. The package masqueraded as an HTTP request library but secretly monitored responses for specific fields and executed their content without user knowledge.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of reqcrypt-dev package
- Ecosystems
- Attack vectors
- Affected entities
- reqcrypt-devPyPI package containing hidden backdoor
The PyPI package reqcrypt-dev was identified as containing malicious code by the OpenSSF malicious-packages project. The package presented itself as an HTTP request library with additional functionality, but included a hidden backdoor mechanism.\n\nOn every usage, the malicious code secretly checks for the presence of specific fields in HTTP responses. If those fields are detected, their content is automatically executed, allowing remote code execution without the user's knowledge or consent.\n\nThe malicious package was attributed to campaign 2026-08-reqcrypt and classified as having clearly malicious intent. The incident was disclosed on 2026-08-19 via GitHub Security Advisory GHSA-f4gc-vf6c-945w.
Indicators of compromise
- Packages
- reqcrypt-dev
Remediation
- Remove reqcrypt-dev from all environments immediately
- Audit systems that installed or used reqcrypt-dev for signs of compromise
- Review HTTP responses and network traffic from systems that used this package for suspicious activity
- Use a legitimate HTTP request library (e.g., requests, httpx) as a replacement
- Check dependency trees for any projects that may have included reqcrypt-dev as a transitive dependency
Sources
- GitHub Advisory GHSA-f4gc-vf6c-945w · GitHub Advisory Database
Cite this entry
"Malicious code in reqcrypt-dev (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 19, 2026; last updated August 19, 2026. https://supplychainattack.org/incident/malicious-code-in-reqcrypt-dev-pypi-h2xdqp
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in scrambleeeer (PyPI)
The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.
2026 08 ScrambleeerPyPICompromised package - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit - containedcritical
Malicious code in boto4 (PyPI)
A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.
2026 08 Boto4PyPICompromised package - containedcritical
Malicious code in scrambleeer (PyPI)
The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.
2026 08 ScrambleeerPyPICompromised package