Logo
pypi

0requests@0.0.1

Vulnerability report · Last retrieved from osv.dev September 3, 2026 at 9:55 PM UTC

Malicious

OSV ID

MAL-2026-15859

Ecosystem

pypi

Summary

During import, the code exfiltrates potentially sensitive env variables. In all analyzed versions the exfiltration target was a localhost, suggesting it was just a test. --- Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities. Campaign: 2026-09-0requests Reasons (based on the campaign): - exfiltration-env-variables - typosquatting

Source: kam193 (b42d4eed37375dfa065db35c2e08365b9557b442c935e645b3e82564c4c32d7c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.