Supply-chain threat intelligence

Incident detail

criticalpypi·typosquatting·osv

Malicious code in reguestsc (PyPI)

reguestsc

Risk score

92

AI summary

Indexed incident for reguestsc (pypi).

Description

Clones of a legitimate library with injected code downloading and executing a malicious executable on import. Dynamic analysis identified it as salatstealer.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-reguestsc

Reasons (based on the campaign):

  • typosquatting

  • Downloads and executes a remote executable.

  • malware

  • clones-real-package

  • spyware-like

  • infostealer

Technical details

Affected versions

=2.34.2

Indicators

  • affected version=2.34.275%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents