-= Per source details. Do not edit below this line.=-
Clone of the requests package that modified the code to send all get and post requests to a hardcoded URL
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-01-rqsts
Reasons (based on the campaign):
clones-real-package
dependency-confusion
action-hidden-in-lib-usage
{
"malicious-packages-origins": [
{
"sha256": "043d9ce2e45f8664489ff09e45cc8da71167e8c8afd701d349cb62f0a56d5a1f",
"id": "RLMA-2025-01234",
"versions": [
"2.28.1"
],
"import_time": "2025-03-03T15:07:16.968179613Z",
"modified_time": "2025-03-03T13:45:15Z",
"source": "reversing-labs"
},
{
"sha256": "cae844115e69e37d56e1c68eded05d0dfad6b2a584f999ef7e79fc1e4c86ce49",
"id": "pypi/2025-01-rqsts/requesra",
"modified_time": "2025-01-25T16:53:01Z",
"import_time": "2025-12-02T22:30:55.53593581Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"source": "kam193"
},
{
"sha256": "42ce5266dc952340618c995bfe692bd0f801b7b3d098188739aa66038074122e",
"id": "pypi/2025-01-rqsts/requesra",
"modified_time": "2025-01-25T16:53:01Z",
"import_time": "2025-12-02T23:07:18.57383349Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"source": "kam193"
},
{
"sha256": "5020d0764d9327f6e9bc3a07d2c336edfc877455c3f7b3f0ea7cfd9f29742ff9",
"id": "pypi/2025-01-rqsts/requesra",
"versions": [
"2.28.1"
],
"import_time": "2025-12-10T21:38:57.782698229Z",
"modified_time": "2025-01-25T16:53:01Z",
"source": "kam193"
},
{
"sha256": "9ffafa26590e662a696d1b8cff78902addb6f20a38f7a916815fc43189622aee",
"id": "RLUA-2026-00702",
"modified_time": "2026-03-18T12:18:10Z",
"import_time": "2026-03-19T12:20:22.228014878Z",
"source": "reversing-labs"
}
]
}