MAL-2026-11413
Dashboard / Malicious Package / MAL-2026-11413
MAL-2026-11413
Summary: Malicious code in reguestsc (PyPI)
Details: Source: kam193 (20e4ae2ce79408a65e9b4bb348c2d69e20eb6072e3641531e2ec5773f1bbddd6) Clones of a legitimate library with injected code downloading and executing a malicious executable on import. Dynamic analysis identified it as salatstealer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-reguestsc Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - malware - clones-real-package - spyware-like - infostealer
References: https://www.virustotal.com/gui/file/db86ed61afec83acb523e8b00558ee7641b2ddc388d542dc0ff2922625da013f/detection, https://tria.ge/260731-kqvw2aff97/behavioral1, https://app.any.run/tasks/348751a8-657c-4a3d-bee1-dedae5264036, https://bad-packages.kam193.eu/pypi/package/reguestsc
Affected packages
Package
Name: reguestsc
Purl: pkg:pypi/reguestsc
Affected ranges
Type: N/A
Events:
