MAL-2025-6575
Dashboard / Malicious Package / MAL-2025-6575
MAL-2025-6575
Summary: Malicious code in rehttps (PyPI)
Details: Source: kam193 (08172961784989f62b2b0793fa7686e1c25883883f790293df61591aa2fc6940) During installation, package attempts to download and starts an executable. The package itself is a clone of requests Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-06-rehttps Reasons (based on the campaign): - clones-real-package - The package overrides the install command in setup.py to execute malicious code during installation.
References: https://www.virustotal.com/gui/file/08ba6289e5c338b446a9551cec8e818321299c72c844d13cf2a0601a37fb8e52/detection, https://bad-packages.kam193.eu/pypi/package/rehttps
Affected packages
Package
Name: rehttps
Purl: pkg:pypi/rehttps
Affected ranges
Type: N/A
Events:
