Malicious code in requests-crypt (PyPI)
The PyPI package requests-crypt contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of malicious package versions
- Ecosystems
- Attack vectors
- Affected entities
- requests-cryptPyPI package containing hidden backdoor
The PyPI package requests-crypt has been identified as containing malicious code by the OpenSSF malicious-packages project. The package presents itself as an HTTP request library with additional functionality, but includes a hidden backdoor mechanism.\n\nOn every usage, the malicious code secretly checks for the presence of specific fields in HTTP responses. If these fields are detected, their content is automatically executed, allowing remote code execution without user awareness or consent.\n\nThis represents a clear supply chain attack with infosteal and remote execution capabilities. The campaign identifier is 2026-08-reqcrypt, and the malicious package was identified and cataloged by the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- requests-crypt
Remediation
- Immediately uninstall requests-crypt from all systems
- Audit systems that installed or used requests-crypt for signs of compromise
- Review HTTP traffic logs for suspicious response patterns that may have triggered the backdoor
- Rotate credentials and secrets on affected systems
- Monitor for indicators of compromise such as unexpected outbound connections or process execution
- Use a legitimate HTTP request library (e.g., requests) as a replacement
Sources
- GitHub Advisory GHSA-cf52-hr54-m53p · GitHub Advisory Database
Cite this entry
"Malicious code in requests-crypt (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 21, 2026; last updated August 21, 2026. https://supplychainattack.org/incident/malicious-code-in-requests-crypt-pypi-tnnsyr
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in mlflow-otel-instrumentor (PyPI)
A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.
PyPITyposquattingCompromised package - containedcritical
Malicious code in cryptgraphy (PyPI)
A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.
2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting - containedcritical
Malicious code in scrambleeeer (PyPI)
The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.
2026 08 ScrambleeerPyPICompromised package - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit