{"id":"MAL-2022-7439","summary":"Malicious code in requestts (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: checkmarx (0c0ffc8f86c690c110698019cf875b931478cfd7c059ea4da99532950ae57829)\nMalicious packages typosquatting the popular requests package. payload execute a cryptomining malware\n","modified":"2022-05-31T20:12:58Z","published":"2022-05-31T00:00:00Z","database_specific":{"iocs":{"domains":["serene-springs-50769.herokuapp.com"],"strings":["44ZptWtXxVhjLYGz8oKCMSW6nA9Gpc2RVYQDzyBnaM7VZkaCTGZGEANQTR3pNXK3mzZq1cVzKs1SA3H4Wibc6qVvG5xpcSY"]},"malicious-packages-origins":[{"import_time":"2023-09-04T09:20:36.389426574Z","modified_time":"2022-05-31T20:12:58Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"0c0ffc8f86c690c110698019cf875b931478cfd7c059ea4da99532950ae57829","source":"checkmarx"}]},"references":[{"type":"ARTICLE","url":"https://medium.com/checkmarx-security/typosquatting-attack-on-requests-one-of-the-most-popular-python-packages-3b0a329a892d"}],"affected":[{"package":{"name":"requestts","ecosystem":"PyPI","purl":"pkg:pypi/requestts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/requestts/MAL-2022-7439.json"}}],"schema_version":"1.7.3","credits":[{"name":"Checkmarx","contact":["supplychainsecurity@checkmarx.com","https://bit.ly/checkmarx-malicious-packages"],"type":"FINDER"}]}