Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in requests-crypt (PyPI)

The PyPI package requests-crypt contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of malicious package versions
Ecosystems
Attack vectors
Affected entities
  • requests-cryptPyPI package containing hidden backdoor

The PyPI package requests-crypt has been identified as containing malicious code by the OpenSSF malicious-packages project. The package presents itself as an HTTP request library with additional functionality, but includes a hidden backdoor mechanism.\n\nOn every usage, the malicious code secretly checks for the presence of specific fields in HTTP responses. If these fields are detected, their content is automatically executed, allowing remote code execution without user awareness or consent.\n\nThis represents a clear supply chain attack with infosteal and remote execution capabilities. The campaign identifier is 2026-08-reqcrypt, and the malicious package was identified and cataloged by the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • requests-crypt

Remediation

  • Immediately uninstall requests-crypt from all systems
  • Audit systems that installed or used requests-crypt for signs of compromise
  • Review HTTP traffic logs for suspicious response patterns that may have triggered the backdoor
  • Rotate credentials and secrets on affected systems
  • Monitor for indicators of compromise such as unexpected outbound connections or process execution
  • Use a legitimate HTTP request library (e.g., requests) as a replacement

Sources

  1. GitHub Advisory GHSA-cf52-hr54-m53p · GitHub Advisory Database

Cite this entry

"Malicious code in requests-crypt (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 21, 2026; last updated August 21, 2026. https://supplychainattack.org/incident/malicious-code-in-requests-crypt-pypi-tnnsyr

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in cryptgraphy (PyPI)

    A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.

    2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting
  3. containedcritical

    Malicious code in scrambleeeer (PyPI)

    The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.

    2026 08 ScrambleeerPyPICompromised package
  4. containedcritical

    Malicious code in reqcrypts (PyPI)

    The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.

    2026 08 ReqcryptPyPICompromised packageMalicious commit