MAL-2026-843

    Dashboard / Malicious Package / MAL-2026-843

    MAL-2026-843

    Published: 10 Feb 2026Last Modified: 10 Feb 2026

    Summary: Malicious code in requests-core-plugin (PyPI)

    Details: Source: kam193 (f7d809caa4cb4961377b3c02a06f90ce19136a36297191248a8c6cd289a809f2) During installation, package loads obfuscated code that then downloads and starts an executable. The final executable is identified as malware and appears to have infostealer capabilities (collecting browser and Discord data). Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-requests-core-plugin Reasons (based on the campaign): - malware - The package overrides the install command in setup.py to execute malicious code during installation. - impersonation - obfuscation - infostealer

    Affected packages

    Package

    Name: requests-core-plugin

    Purl: pkg:pypi/requests-core-plugin

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.31.5
    2.31.6
    2.31.7
    2.31.8
    2.31.9
    2.31.12
    2.31.13
    2.31.14
    2.31.15