MAL-2026-1240

    Dashboard / Malicious Package / MAL-2026-1240

    MAL-2026-1240

    Published: 4 Mar 2026Last Modified: 23 Mar 2026

    Summary: Malicious code in requests-ml-min (PyPI)

    Details: Source: kam193 (caf988849523549406a61384e2c9f8e01d6edf3ad71e5cba77ca7c3987863f1d) During installation, the package starts obfuscated code that downloads and runs remote executables in specific environments. In some packages in the campaign, the code only attempts to exfiltrate some basic information using DNS requests and then likely cover tracks by installing a similarly named package from private repository Related campaigns: 2026-02-spark-audit-notify, 2026-03-geekennedy Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-urllib-slim Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - obfuscation - dependency-confusion

    Affected packages

    Package

    Name: requests-ml-min

    Purl: pkg:pypi/requests-ml-min

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.45
    MAL-2026-1240 | CVE-DB