pypi
Malicious requetses @0.5
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 9:32 AM UTC
OSV ID
MAL-2025-974
Ecosystem
pypi
Summary
Under a typosquatting name there is a package prepared to exfiltrate photos from a phone, although it requires external trigger. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-12-requetses Reasons (based on the campaign): - typosquatting - files-exfiltration
Source: kam193 (d43e83ac1c0257aa1168edf9c20430524b46520f60a5f5a0c0e1c2040afa0c87)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.