MAL-2026-14130

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/httpz-requests/MAL-2026-14130.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14130
Published
2026-08-18T19:24:17Z
Modified
2026-08-19T00:30:18.065538569Z
Summary
Malicious code in httpz-requests (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (004770b4da0c6705f95ef2c8654fd81d37650ffacaad7160041bded02cdb7fbc)

httpz-requests exposes a Telegram bot (start_bot, run_cmd_enc, http_request) whose message handler executes arbitrary shell commands on the host running the package, granting a remote Telegram operator full command execution under the installer's user account. Documented remote commands include arbitrary shell execution (chalao, .sh <command>, .py <file>, .exec <file>), destructive filesystem operations (rm -rf <path>), single- and bulk-file exfiltration (take <file>, take all), a full-host backup mode that produces split 50MB archives with .partNNN chunking (get all), and environment-variable dumping (.printenv) — collectively enabling remote theft of filesystem contents and process-environment secrets (cloud, CI, and API credentials). The package is shipped only as compiled Cython .so files with no Python source, and self-describes obfuscation features that XOR+base64-encode command strings and disguise execution as http_request("POST",...) so plaintext commands do not appear in ps or system logs; the Telegram bot token is stored encoded and decoded at runtime by dec(). The distribution name httpz-requests and import name httpz_requests resemble the top-100 PyPI package requests while presenting a Telegram remote-shell API instead of an HTTP client, and metadata is unfilled boilerplate (author Aapka Naam <you@example.com>, homepage https://github.com/YOUR_GITHUB_USERNAME/httpz-requests).

Source: kam193 (38eff923106836997e28de6d7173a1553da126be230b341fe64f0c4c215769a2)

The package provides Telegram-based remote access to the machine it runs on. It was deliberately created and used to hack other machines, exfiltrate files and credentials. This package automatically ensures persistence and starts a malicious process on import.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-httpz-requests

Reasons (based on the campaign):

  • files-exfiltration

  • rat

  • persistence

  • uses-telegram-bot

  • obfuscation

  • native-extension

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-18T20:09:14.489828058Z",
            "sha256": "38eff923106836997e28de6d7173a1553da126be230b341fe64f0c4c215769a2",
            "modified_time": "2026-08-18T19:24:17.241503Z",
            "source": "kam193",
            "id": "pypi/2026-08-httpz-requests/httpz-requests",
            "versions": [
                "1.8.0",
                "1.9.0",
                "1.10.0",
                "1.11.0",
                "1.12.0",
                "1.13.0",
                "1.14.0",
                "1.15.0",
                "1.16.0",
                "1.17.0",
                "1.18.0",
                "1.19.0",
                "1.20.0",
                "1.21.0",
                "1.21.1",
                "1.21.2",
                "1.21.3",
                "1.21.4",
                "1.21.5",
                "1.21.6",
                "1.21.7",
                "1.21.8",
                "1.21.9",
                "1.21.10",
                "1.21.11",
                "1.21.12",
                "1.21.13",
                "1.21.14",
                "1.21.15",
                "1.21.16",
                "1.21.17",
                "1.21.18",
                "1.21.19",
                "1.21.20"
            ]
        },
        {
            "import_time": "2026-08-18T21:10:36.386765808Z",
            "sha256": "bfd397d38ebfc99250d82313fa10e56a8ef5c7f8fa2d8f6936ee9c3c2964b54f",
            "modified_time": "2026-08-18T19:24:17.241503Z",
            "source": "kam193",
            "id": "pypi/2026-08-httpz-requests/httpz-requests",
            "versions": [
                "1.8.0",
                "1.9.0",
                "1.10.0",
                "1.11.0",
                "1.12.0",
                "1.13.0",
                "1.14.0",
                "1.15.0",
                "1.16.0",
                "1.17.0",
                "1.18.0",
                "1.19.0",
                "1.20.0",
                "1.21.0",
                "1.21.1",
                "1.21.2",
                "1.21.3",
                "1.21.4",
                "1.21.5",
                "1.21.6",
                "1.21.7",
                "1.21.8",
                "1.21.9",
                "1.21.10",
                "1.21.11",
                "1.21.12",
                "1.21.13",
                "1.21.14",
                "1.21.15",
                "1.21.16",
                "1.21.17",
                "1.21.18",
                "1.21.19",
                "1.21.20"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:09.371342286Z",
            "sha256": "4835ca3a578fd956c23ec847cd0ac56cadbd9b2f34a430bf5ce1d7671b365615",
            "modified_time": "2026-08-18T23:46:47Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018214",
            "versions": [
                "1.14.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:09.166953052Z",
            "sha256": "e3c9badecdb264941a793175933b8011d05b22978a718ae9fb0fbe1b9400a64c",
            "modified_time": "2026-08-18T23:46:27Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018212",
            "versions": [
                "1.16.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:07.877404017Z",
            "sha256": "f9b2ddbdc983c898d2b86dbd97247a6242c38b7d9664968ce1c842203eebfb71",
            "modified_time": "2026-08-18T23:44:11Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018198",
            "versions": [
                "1.11.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.313248429Z",
            "sha256": "15d9f40ec1463a539ec3e5c7ecf783947bc724e302fdf21d428b82ad02560644",
            "modified_time": "2026-08-18T23:44:50Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018203",
            "versions": [
                "1.21.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.238752268Z",
            "sha256": "4170d438607fc1bf9fcb14aa7cb601d77944a80853999bde9edc97747c24dc01",
            "modified_time": "2026-08-18T23:44:41Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018202",
            "versions": [
                "1.21.2"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.789298654Z",
            "sha256": "69689b730524ba61bd510852948f81de1265339089b856189d34921e6b94541f",
            "modified_time": "2026-08-18T23:45:34Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018208",
            "versions": [
                "1.21.4"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:09.581392791Z",
            "sha256": "84faf8868c133d003132a1396b91954a487bfc6e9726457960ea6f51e8b1feec",
            "modified_time": "2026-08-18T23:47:03Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018216",
            "versions": [
                "1.13.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.536973049Z",
            "sha256": "b46aaafe9b6008f1c4a2b41b173376fe992bc2179026019d0c3f75bf04eeb20f",
            "modified_time": "2026-08-18T23:45:08Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018205",
            "versions": [
                "1.19.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.871556778Z",
            "source": "amazon-inspector",
            "modified_time": "2026-08-18T23:46:00Z",
            "sha256": "bfc37d6b5acd1e4dc8353caed214395be65a994b22c47675e863638e25b4114e",
            "id": "IN-MAL-2026-018209",
            "versions": [
                "1.21.5"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:07.776998992Z",
            "sha256": "d99ea02f5a4160922b5f4680cf364f520d08553e5af297ee80537c02c5e90838",
            "modified_time": "2026-08-18T23:44:03Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018197",
            "versions": [
                "1.21.1"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.069606262Z",
            "sha256": "004770b4da0c6705f95ef2c8654fd81d37650ffacaad7160041bded02cdb7fbc",
            "modified_time": "2026-08-18T23:44:25Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018200",
            "versions": [
                "1.10.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.700177039Z",
            "source": "amazon-inspector",
            "modified_time": "2026-08-18T23:45:27Z",
            "sha256": "3f09dc685ac9d90fb6021dc7419466544c717e4b7f90c3c48c57c0f411044a94",
            "id": "IN-MAL-2026-018207",
            "versions": [
                "1.21.3"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:07.97771446Z",
            "sha256": "57031a96370ea7ae754a733c1c1fc8c93b2394c1ddcbb28b126f0f030f4055f3",
            "modified_time": "2026-08-18T23:44:18Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018199",
            "versions": [
                "1.15.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.434561639Z",
            "sha256": "9479a250d61d2058bbf37a89f74d5eaaa9218495c2b05896ce17b6c2f9973017",
            "modified_time": "2026-08-18T23:45:01Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018204",
            "versions": [
                "1.18.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.157248607Z",
            "source": "amazon-inspector",
            "modified_time": "2026-08-18T23:44:33Z",
            "sha256": "afd39f4774edc5f826de98ce9379269b7ee282eaf84e3b2f4bc7a27e6b8b6a51",
            "id": "IN-MAL-2026-018201",
            "versions": [
                "1.12.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:09.272012205Z",
            "sha256": "bf64eb40508632888cfa2827047f1cde21c8e236ca6ddb115907dbae835cc230",
            "modified_time": "2026-08-18T23:46:34Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018213",
            "versions": [
                "1.17.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:09.066052239Z",
            "source": "amazon-inspector",
            "modified_time": "2026-08-18T23:46:19Z",
            "sha256": "3b5bc3a5b6ca5690efc85fdff29e1d122f0536719c58449a5925973203d79fba",
            "id": "IN-MAL-2026-018211",
            "versions": [
                "1.8.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.62315327Z",
            "sha256": "c27aeb1f1723947523f3e14b8656f1982821285b249077416c34557671094946",
            "modified_time": "2026-08-18T23:45:16Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018206",
            "versions": [
                "1.20.0"
            ]
        },
        {
            "import_time": "2026-08-19T00:21:08.973723823Z",
            "source": "amazon-inspector",
            "modified_time": "2026-08-18T23:46:12Z",
            "sha256": "c7eb1009a920f3e6b5d8a0dffec9df9ecef54cf27d7938fac70dcdc4c62817c9",
            "id": "IN-MAL-2026-018210",
            "versions": [
                "1.9.0"
            ]
        }
    ],
    "iocs": {
        "domains": [
            "spy-storage-bot.vercel.app"
        ]
    }
}
References
Credits

Affected packages

PyPI / httpz-requests

Package

Affected ranges

Affected versions

1.*
1.8.0
1.9.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.21.9
1.21.10
1.21.11
1.21.12
1.21.13
1.21.14
1.21.15
1.21.16
1.21.17
1.21.18
1.21.19
1.21.20

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/httpz-requests/MAL-2026-14130.json"
indicators
{
    "evidence_files": [
        {
            "sha256": "94e5a3d489ca119f4ea6dd7aa345cf945865a04bd00f0713853811f6d2efe8b1",
            "path": "httpz_requests/__init__.py"
        },
        {
            "sha256": "0b5cb476362e661610850dc18dae2ac1f9b7c5f89427751c08b71bb6030a3b02",
            "tlsh": "f55184f301c8bc967be28d4b97599b268826f771794c64f838fda06e0b511a2c27c038",
            "path": "httpz_requests-1.14.0.dist-info/METADATA"
        }
    ],
    "package_integrity": [
        {
            "filename": "httpz_requests-1.14.0-py3-none-any.whl",
            "hashes": {
                "blake2b_256": "d57d9c6e3ce82f84d55460114656d809a6d217e4e648ccbb891b06442b85e9aa",
                "sha256": "4c32fb175abfbda38e1d2006df53e2af3dfc8010806d9e5556e5bf9ca8da3d6f",
                "md5": "e3ef40acf9c87a3e1a84f8ccc61085ef"
            }
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]