-= Per source details. Do not edit below this line.=-
httpz-requests exposes a Telegram bot (start_bot, run_cmd_enc, http_request) whose message handler executes arbitrary shell commands on the host running the package, granting a remote Telegram operator full command execution under the installer's user account. Documented remote commands include arbitrary shell execution (chalao, .sh <command>, .py <file>, .exec <file>), destructive filesystem operations (rm -rf <path>), single- and bulk-file exfiltration (take <file>, take all), a full-host backup mode that produces split 50MB archives with .partNNN chunking (get all), and environment-variable dumping (.printenv) — collectively enabling remote theft of filesystem contents and process-environment secrets (cloud, CI, and API credentials). The package is shipped only as compiled Cython .so files with no Python source, and self-describes obfuscation features that XOR+base64-encode command strings and disguise execution as http_request("POST",...) so plaintext commands do not appear in ps or system logs; the Telegram bot token is stored encoded and decoded at runtime by dec(). The distribution name httpz-requests and import name httpz_requests resemble the top-100 PyPI package requests while presenting a Telegram remote-shell API instead of an HTTP client, and metadata is unfilled boilerplate (author Aapka Naam <you@example.com>, homepage https://github.com/YOUR_GITHUB_USERNAME/httpz-requests).
The package provides Telegram-based remote access to the machine it runs on. It was deliberately created and used to hack other machines, exfiltrate files and credentials. This package automatically ensures persistence and starts a malicious process on import.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-httpz-requests
Reasons (based on the campaign):
files-exfiltration
rat
persistence
uses-telegram-bot
obfuscation
native-extension
{
"malicious-packages-origins": [
{
"import_time": "2026-08-18T20:09:14.489828058Z",
"sha256": "38eff923106836997e28de6d7173a1553da126be230b341fe64f0c4c215769a2",
"modified_time": "2026-08-18T19:24:17.241503Z",
"source": "kam193",
"id": "pypi/2026-08-httpz-requests/httpz-requests",
"versions": [
"1.8.0",
"1.9.0",
"1.10.0",
"1.11.0",
"1.12.0",
"1.13.0",
"1.14.0",
"1.15.0",
"1.16.0",
"1.17.0",
"1.18.0",
"1.19.0",
"1.20.0",
"1.21.0",
"1.21.1",
"1.21.2",
"1.21.3",
"1.21.4",
"1.21.5",
"1.21.6",
"1.21.7",
"1.21.8",
"1.21.9",
"1.21.10",
"1.21.11",
"1.21.12",
"1.21.13",
"1.21.14",
"1.21.15",
"1.21.16",
"1.21.17",
"1.21.18",
"1.21.19",
"1.21.20"
]
},
{
"import_time": "2026-08-18T21:10:36.386765808Z",
"sha256": "bfd397d38ebfc99250d82313fa10e56a8ef5c7f8fa2d8f6936ee9c3c2964b54f",
"modified_time": "2026-08-18T19:24:17.241503Z",
"source": "kam193",
"id": "pypi/2026-08-httpz-requests/httpz-requests",
"versions": [
"1.8.0",
"1.9.0",
"1.10.0",
"1.11.0",
"1.12.0",
"1.13.0",
"1.14.0",
"1.15.0",
"1.16.0",
"1.17.0",
"1.18.0",
"1.19.0",
"1.20.0",
"1.21.0",
"1.21.1",
"1.21.2",
"1.21.3",
"1.21.4",
"1.21.5",
"1.21.6",
"1.21.7",
"1.21.8",
"1.21.9",
"1.21.10",
"1.21.11",
"1.21.12",
"1.21.13",
"1.21.14",
"1.21.15",
"1.21.16",
"1.21.17",
"1.21.18",
"1.21.19",
"1.21.20"
]
},
{
"import_time": "2026-08-19T00:21:09.371342286Z",
"sha256": "4835ca3a578fd956c23ec847cd0ac56cadbd9b2f34a430bf5ce1d7671b365615",
"modified_time": "2026-08-18T23:46:47Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018214",
"versions": [
"1.14.0"
]
},
{
"import_time": "2026-08-19T00:21:09.166953052Z",
"sha256": "e3c9badecdb264941a793175933b8011d05b22978a718ae9fb0fbe1b9400a64c",
"modified_time": "2026-08-18T23:46:27Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018212",
"versions": [
"1.16.0"
]
},
{
"import_time": "2026-08-19T00:21:07.877404017Z",
"sha256": "f9b2ddbdc983c898d2b86dbd97247a6242c38b7d9664968ce1c842203eebfb71",
"modified_time": "2026-08-18T23:44:11Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018198",
"versions": [
"1.11.0"
]
},
{
"import_time": "2026-08-19T00:21:08.313248429Z",
"sha256": "15d9f40ec1463a539ec3e5c7ecf783947bc724e302fdf21d428b82ad02560644",
"modified_time": "2026-08-18T23:44:50Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018203",
"versions": [
"1.21.0"
]
},
{
"import_time": "2026-08-19T00:21:08.238752268Z",
"sha256": "4170d438607fc1bf9fcb14aa7cb601d77944a80853999bde9edc97747c24dc01",
"modified_time": "2026-08-18T23:44:41Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018202",
"versions": [
"1.21.2"
]
},
{
"import_time": "2026-08-19T00:21:08.789298654Z",
"sha256": "69689b730524ba61bd510852948f81de1265339089b856189d34921e6b94541f",
"modified_time": "2026-08-18T23:45:34Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018208",
"versions": [
"1.21.4"
]
},
{
"import_time": "2026-08-19T00:21:09.581392791Z",
"sha256": "84faf8868c133d003132a1396b91954a487bfc6e9726457960ea6f51e8b1feec",
"modified_time": "2026-08-18T23:47:03Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018216",
"versions": [
"1.13.0"
]
},
{
"import_time": "2026-08-19T00:21:08.536973049Z",
"sha256": "b46aaafe9b6008f1c4a2b41b173376fe992bc2179026019d0c3f75bf04eeb20f",
"modified_time": "2026-08-18T23:45:08Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018205",
"versions": [
"1.19.0"
]
},
{
"import_time": "2026-08-19T00:21:08.871556778Z",
"source": "amazon-inspector",
"modified_time": "2026-08-18T23:46:00Z",
"sha256": "bfc37d6b5acd1e4dc8353caed214395be65a994b22c47675e863638e25b4114e",
"id": "IN-MAL-2026-018209",
"versions": [
"1.21.5"
]
},
{
"import_time": "2026-08-19T00:21:07.776998992Z",
"sha256": "d99ea02f5a4160922b5f4680cf364f520d08553e5af297ee80537c02c5e90838",
"modified_time": "2026-08-18T23:44:03Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018197",
"versions": [
"1.21.1"
]
},
{
"import_time": "2026-08-19T00:21:08.069606262Z",
"sha256": "004770b4da0c6705f95ef2c8654fd81d37650ffacaad7160041bded02cdb7fbc",
"modified_time": "2026-08-18T23:44:25Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018200",
"versions": [
"1.10.0"
]
},
{
"import_time": "2026-08-19T00:21:08.700177039Z",
"source": "amazon-inspector",
"modified_time": "2026-08-18T23:45:27Z",
"sha256": "3f09dc685ac9d90fb6021dc7419466544c717e4b7f90c3c48c57c0f411044a94",
"id": "IN-MAL-2026-018207",
"versions": [
"1.21.3"
]
},
{
"import_time": "2026-08-19T00:21:07.97771446Z",
"sha256": "57031a96370ea7ae754a733c1c1fc8c93b2394c1ddcbb28b126f0f030f4055f3",
"modified_time": "2026-08-18T23:44:18Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018199",
"versions": [
"1.15.0"
]
},
{
"import_time": "2026-08-19T00:21:08.434561639Z",
"sha256": "9479a250d61d2058bbf37a89f74d5eaaa9218495c2b05896ce17b6c2f9973017",
"modified_time": "2026-08-18T23:45:01Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018204",
"versions": [
"1.18.0"
]
},
{
"import_time": "2026-08-19T00:21:08.157248607Z",
"source": "amazon-inspector",
"modified_time": "2026-08-18T23:44:33Z",
"sha256": "afd39f4774edc5f826de98ce9379269b7ee282eaf84e3b2f4bc7a27e6b8b6a51",
"id": "IN-MAL-2026-018201",
"versions": [
"1.12.0"
]
},
{
"import_time": "2026-08-19T00:21:09.272012205Z",
"sha256": "bf64eb40508632888cfa2827047f1cde21c8e236ca6ddb115907dbae835cc230",
"modified_time": "2026-08-18T23:46:34Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018213",
"versions": [
"1.17.0"
]
},
{
"import_time": "2026-08-19T00:21:09.066052239Z",
"source": "amazon-inspector",
"modified_time": "2026-08-18T23:46:19Z",
"sha256": "3b5bc3a5b6ca5690efc85fdff29e1d122f0536719c58449a5925973203d79fba",
"id": "IN-MAL-2026-018211",
"versions": [
"1.8.0"
]
},
{
"import_time": "2026-08-19T00:21:08.62315327Z",
"sha256": "c27aeb1f1723947523f3e14b8656f1982821285b249077416c34557671094946",
"modified_time": "2026-08-18T23:45:16Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-018206",
"versions": [
"1.20.0"
]
},
{
"import_time": "2026-08-19T00:21:08.973723823Z",
"source": "amazon-inspector",
"modified_time": "2026-08-18T23:46:12Z",
"sha256": "c7eb1009a920f3e6b5d8a0dffec9df9ecef54cf27d7938fac70dcdc4c62817c9",
"id": "IN-MAL-2026-018210",
"versions": [
"1.9.0"
]
}
],
"iocs": {
"domains": [
"spy-storage-bot.vercel.app"
]
}
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/httpz-requests/MAL-2026-14130.json"
{
"evidence_files": [
{
"sha256": "94e5a3d489ca119f4ea6dd7aa345cf945865a04bd00f0713853811f6d2efe8b1",
"path": "httpz_requests/__init__.py"
},
{
"sha256": "0b5cb476362e661610850dc18dae2ac1f9b7c5f89427751c08b71bb6030a3b02",
"tlsh": "f55184f301c8bc967be28d4b97599b268826f771794c64f838fda06e0b511a2c27c038",
"path": "httpz_requests-1.14.0.dist-info/METADATA"
}
],
"package_integrity": [
{
"filename": "httpz_requests-1.14.0-py3-none-any.whl",
"hashes": {
"blake2b_256": "d57d9c6e3ce82f84d55460114656d809a6d217e4e648ccbb891b06442b85e9aa",
"sha256": "4c32fb175abfbda38e1d2006df53e2af3dfc8010806d9e5556e5bf9ca8da3d6f",
"md5": "e3ef40acf9c87a3e1a84f8ccc61085ef"
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]