MAL-2024-12338

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/requesr/MAL-2024-12338.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12338
Published
2024-12-24T18:09:49Z
Modified
2025-12-31T02:56:37.906121Z
Summary
Malicious code in requesr (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (b792f17b467610a1021820a7718884aa436487a9ec75d5ebf889d400efeaec24)

Importing the module downloads and starts an infostealer attempting to exfiltrate data and establishing persistence through autorun directory.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-12-reqesst

Reasons (based on the campaign):

  • infostealer

  • peristence-autorun

  • typosquatting

  • exfiltration-generic

  • Downloads and executes a remote executable.

  • clones-real-package

  • dependency-confusion

  • exfiltration-browser-data

  • exfiltration-crypto

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "d770e81fd292e7197f38c6d0ae24eba80b80b257f7f1f62901f4f56ad1360af4",
            "source": "kam193",
            "modified_time": "2024-12-24T18:09:49Z",
            "id": "pypi/2024-12-reqesst/requesr",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T22:30:55.534787915Z"
        },
        {
            "sha256": "b792f17b467610a1021820a7718884aa436487a9ec75d5ebf889d400efeaec24",
            "source": "kam193",
            "modified_time": "2024-12-24T18:09:49Z",
            "id": "pypi/2024-12-reqesst/requesr",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T23:07:18.573078823Z"
        },
        {
            "sha256": "ab3aac1ba180fd7c8e4a17edeb7a4e7a8345d73f342e5e78751910ca2876e85c",
            "source": "kam193",
            "modified_time": "2024-12-24T18:09:49Z",
            "id": "pypi/2024-12-reqesst/requesr",
            "versions": [
                "2.32.3",
                "2.32.2"
            ],
            "import_time": "2025-12-10T21:38:57.78182982Z"
        },
        {
            "sha256": "a1ee8dfb075ecc00ec6f59ffc7500417dc3f1837ff205d96d7dc9a7d9fb817d0",
            "source": "kam193",
            "modified_time": "2024-12-24T18:09:49Z",
            "id": "pypi/2024-12-reqesst/requesr",
            "versions": [
                "2.32.2",
                "2.32.3"
            ],
            "import_time": "2025-12-30T22:39:04.16079217Z"
        }
    ],
    "iocs": {
        "urls": [
            "https://www.dropbox.com/scl/fi/d4ftoxxvovr12f4tjh0mc/H7Glqp2Vy.exe?rlkey=z323u7r1ipm2tegn2dqlqzv9l&st=9gg48qpa&dl=1"
        ]
    }
}
References
Credits

Affected packages

PyPI / requesr

Package

Affected ranges

Affected versions

2.*
2.32.2
2.32.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/requesr/MAL-2024-12338.json"