MAL-2026-847

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/requests-auth-toolkit/MAL-2026-847.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-847
Published
2026-02-10T22:45:40Z
Modified
2026-02-10T23:32:05.076953Z
Summary
Malicious code in requests-auth-toolkit (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (03bb4c04410c4e3c58d7292eb47f8f76a2fbe5265abea29826ac910e890350d0)

During installation, package installs a script that listens for remote commands and executes them. The script is also added to autostart configuration and disguised as system application. This package also adds a new SSH keys for further persistence


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-02-devtools-webhook-cicd-utils

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • peristence-autorun

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

  • obfuscation

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-02-10T23:18:03.137923852Z",
            "modified_time": "2026-02-10T22:45:40.901742Z",
            "sha256": "03bb4c04410c4e3c58d7292eb47f8f76a2fbe5265abea29826ac910e890350d0",
            "source": "kam193",
            "versions": [
                "2.1.0"
            ],
            "id": "pypi/2026-02-devtools-webhook-cicd-utils/requests-auth-toolkit"
        }
    ],
    "iocs": {
        "ips": [
            "77.246.103.245"
        ]
    }
}
References
Credits

Affected packages

PyPI / requests-auth-toolkit

Package

Name
requests-auth-toolkit
View open source insights on deps.dev
Purl
pkg:pypi/requests-auth-toolkit

Affected ranges

Affected versions

2.*
2.1.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/requests-auth-toolkit/MAL-2026-847.json"