Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
- Disclosed
- Last updated
- Blast radius
- All users of the reqcrypts package from PyPI
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- reqcryptsPyPI package containing hidden backdoor
The reqcrypts package published on PyPI was found to contain malicious code implementing a hidden backdoor. The package presents itself as an HTTP request library with additional functionality, but conceals malicious behavior.\n\nOn every usage, the backdoor code secretly checks for the presence of specific fields in HTTP responses. If these fields are detected, their content is automatically executed without user consent or awareness. This allows remote code execution through response manipulation.\n\nThe malicious code was identified and attributed to campaign 2026-08-reqcrypt by the OpenSSF's malicious-packages project. The package has been flagged as containing clear malicious intent consistent with infostealers and backdoor functionality.\n\nUsers who have installed or used this package should immediately remove it and audit their systems for compromise.
Indicators of compromise
- Packages
- reqcrypts
Remediation
- Immediately uninstall the reqcrypts package from all affected systems
- Audit system logs and network traffic for suspicious activity or data exfiltration
- Review any systems that used reqcrypts for signs of unauthorized access or code execution
- Rotate credentials and API keys on affected systems
- Monitor for indicators of compromise related to campaign 2026-08-reqcrypt
- Use only verified, trusted HTTP request libraries as replacements
Sources
- GitHub Advisory GHSA-p5hw-cgm2-4cp2 · GitHub Advisory Database
Cite this entry
"Malicious code in reqcrypts (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 21, 2026; last updated August 21, 2026. https://supplychainattack.org/incident/malicious-code-in-reqcrypts-pypi-6x4vr7
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in @years19/n8n-nodes-utils-helper-c (npm)
The npm package @years19/n8n-nodes-utils-helper-c contained a malicious postinstall script that downloads a trojanized Python multidict module from an attacker-controlled server and injects it into the system's Python site-packages directory, enabling arbitrary code execution on any subsequent Python invocation.
npmPyPICompromised packageMalicious commit - containedcritical
Malicious code in neutrl-core (PyPI)
Malicious code was discovered in the neutrl-core PyPI package designed to exfiltrate sensitive credentials including environment variables, SSH keys, and dotenv files. The malicious functionality was hidden in a function disguised as telemetry and activated via commands from an attacker-controlled endpoint. The attack campaign involved a fake GitHub account with backdated commits to establish false credibility.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in alphalend-layouts (PyPI)
The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in aiassistcore (PyPI)
Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit