-= Per source details. Do not edit below this line.=-
request-cache-py impersonates the legitimate requests-cache HTTP caching library. On import request_cache_py, the package's __init__.py starts a background thread that harvests installer-side secrets and POSTs them to a hardcoded attacker Telegram bot.
Observed behaviors:
~/.ssh/ (id_rsa, id_ed25519, id_ecdsa, id_dsa), ~/.aws/credentials, ~/.aws/config, ~/.gitconfig, ~/.git-credentials, ~/.npmrc, ~/.pypirc, ~/.dockercfg, ~/.docker/config.json, plus gcloud and vscode settings.Login Data, Cookies, and History SQLite databases to /tmp and extracts saved logins, cookies, and browsing history (SELECT origin_url, username_value FROM logins; SELECT host_key, name, value, path FROM cookies).os.environ and exfiltrates any variable whose name contains key, token, secret, password, api, or auth.https://api.telegram.org/bot<redacted>/sendMessage with a fixed chat_id. The bot token and chat id are base64-split across pieces and reassembled at runtime to evade scanners._should_skip() aborts when CI, GITHUB_ACTIONS, TRAVIS, JENKINS_HOME, CIRCLECI, /.dockerenv, or hypervisor markers are present, restricting execution to real developer workstations. A ~/.cache/.pyrc marker suppresses repeat sends within 24 hours.The combination — name impersonation of a popular library, import-time credential harvest from classic developer secret paths, browser database theft, env scraping, base64-obfuscated C2, sandbox evasion — is a deliberate supply-chain credential stealer targeting human developers.
During import, package exfiltrates browsers data, SSH keys and other credential files, env variables and other sensitive data.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-request-cache-py
Reasons (based on the campaign):
infostealer
exfiltration-env-variables
exfiltration-ssh-keys
impersonation
A Telegram webhook is used to send collected data.
exfiltration-browser-data
The package contains code to detect if it is running in a sandbox environment.
exfiltration-credentials
The malicious code is intentionally included in a dependency of the package
{
"iocs": {
"domains": [
"analytics-collector.herokuapp.com"
],
"urls": [
"https://analytics-collector.herokuapp.com/events"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-06-request-cache-py/request-cache-py",
"import_time": "2026-06-20T19:34:59.735458632Z",
"modified_time": "2026-06-20T18:49:53.485406Z",
"sha256": "d027c4b6379310432f96b48dc78c73ddf1346052c5ab16ea6ed4fe3fc0754d08",
"source": "kam193",
"versions": [
"1.0.0",
"1.0.1",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.0.9",
"1.1.0"
]
},
{
"id": "IN-MAL-2026-007157",
"import_time": "2026-06-22T18:25:29.643101092Z",
"modified_time": "2026-06-22T18:24:25Z",
"sha256": "4ec4eb5987160de24832dd35975645b14904ca353b22b35740e58aa833ea0b81",
"source": "amazon-inspector",
"versions": [
"1.1.0"
]
},
{
"id": "IN-MAL-2026-007158",
"import_time": "2026-06-22T18:25:29.81285396Z",
"modified_time": "2026-06-22T18:24:26Z",
"sha256": "81fce5abd64051b0a0b385f15f498a2dbde54baf0b2b5cc58a4948b2485f013a",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-007156",
"import_time": "2026-06-22T18:25:29.560400349Z",
"modified_time": "2026-06-22T18:24:25Z",
"sha256": "9c927aa5d62f6f7fa19755c9b10a85001368f6ffa77670da9dccddd806c7d670",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-007159",
"import_time": "2026-06-22T18:25:29.921571037Z",
"modified_time": "2026-06-22T18:24:30Z",
"sha256": "eafb96e46544cb1351d26caf52bff79055bc205a1f8454737b677fff8fbc6fea",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-007160",
"import_time": "2026-06-22T18:25:30.106202738Z",
"modified_time": "2026-06-22T18:24:31Z",
"sha256": "1a042aecdbbad9d841817b51d6d6f9dde1604ead6fb89a9875318a90cdcf3e7a",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-007155",
"import_time": "2026-06-22T18:25:29.488875576Z",
"modified_time": "2026-06-22T18:24:23Z",
"sha256": "3abe06cfd4bc42ce70a746ecbccfcb29e093f620978448c670ab66f0076bc540",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-008572",
"import_time": "2026-07-08T20:32:45.899947813Z",
"modified_time": "2026-07-08T20:30:35Z",
"sha256": "240b3bc782609197c032265d3949dd423b923c62219abcac13c6b20f25b0cf95",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-008879",
"import_time": "2026-07-08T22:51:31.060757619Z",
"modified_time": "2026-07-08T22:46:34Z",
"sha256": "46a5cf1a09ced54f218679c05284e510d84000f462e69fb7d9afb24c2c0b9415",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-008876",
"import_time": "2026-07-08T22:51:30.715826938Z",
"modified_time": "2026-07-08T22:46:07Z",
"sha256": "7a5f558a3ce1a7bbe792e40186a58026a63c2111db5cea0da4325ab69738e604",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-008860",
"import_time": "2026-07-08T22:51:29.017740877Z",
"modified_time": "2026-07-08T22:43:51Z",
"sha256": "91443bcf93f3a44ee9df04f686dd8c01eb089e554619ddfd65567feb4b5a67b1",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-008839",
"import_time": "2026-07-08T22:51:26.469415755Z",
"modified_time": "2026-07-08T22:40:39Z",
"sha256": "9d603139d5b17fd63334a042e856af66f828f098efab4022b3872241dc0a45b5",
"source": "amazon-inspector",
"versions": [
"1.0.9"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "request_cache_py/__init__.py",
"sha256": "f3a42d1dc1e40084acca2668279d9b1ec9568b5ea2e14fb6da1b8f744e3e61c6",
"tlsh": "b272b54626a8b452c383847f8c97e1127b1abd571a50a83c3cec46186fc8176d6f5ebc"
},
{
"path": "setup.py",
"sha256": "7d7188f77fc26ccb8f54495c5b3be1371c7eb4db5b78e050668ea1557a4c1389",
"tlsh": "cf21f0670dc616f06af0844a553f1c06e8258b672600a8d779bd034d6ff3be3027613c"
}
],
"package_integrity": [
{
"filename": "request_cache_py-1.1.0.tar.gz",
"hashes": {
"blake2b_256": "d604aaa98bfa898675959af1a2c1ab6cf35343f74d9503998d89c2c5d69137d1",
"md5": "c723b737df97419d935180cab0ed5062",
"sha256": "1fa0f56e415c0b573ca5279e475e199c5d789761d743770be47cc576cdae0000"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/request-cache-py/MAL-2026-6245.json"