MAL-2026-15859

    Dashboard / Malicious Package / MAL-2026-15859

    MAL-2026-15859

    Published: 3 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in 0requests (PyPI)

    Details: Source: amazon-inspector (ce3a594da2523b6481bd4639f5d3aaed9ec11a9adf92c2b99bf99d0ab6fb5b78) The package name '0requests' is a one-character variant of the popular PyPI package 'requests'. On import of the top-level package, __init__.py enumerates os.environ and collects every variable whose name begins with SECRET, API, TOKEN, or KEY, then opens a TCP socket to a host/port taken from the TS_HOST and TS_PORT environment variables and sends the serialized dictionary of credential-shaped variables. The same import path spawns a python subprocess that connects to the same TS_HOST:TS_PORT, sends a 'SHELL' marker, and sleeps to keep the socket open, providing a remote-controlled shell channel on the host. Console output includes '0requests installed -- targeting requests' and a '[typosquat] exfiltrating' log line, confirming intent. Source: kam193 (b42d4eed37375dfa065db35c2e08365b9557b442c935e645b3e82564c4c32d7c) During import, the code exfiltrates potentially sensitive env variables. In all analyzed versions the exfiltration target was a localhost, suggesting it was just a test. Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities. Campaign: 2026-09-0requests Reasons (based on the campaign): - exfiltration-env-variables - typosquatting

    Affected packages

    Package

    Name: 0requests

    Purl: pkg:pypi/0requests

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1