{"id":"MAL-2026-6245","summary":"Malicious code in request-cache-py (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (eafb96e46544cb1351d26caf52bff79055bc205a1f8454737b677fff8fbc6fea)\nrequest-cache-py impersonates the legitimate requests-cache HTTP caching library. On `import request_cache_py`, the package's `__init__.py` starts a background thread that harvests installer-side secrets and POSTs them to a hardcoded attacker Telegram bot.\n\nObserved behaviors:\n- Reads private keys and credentials from `~/.ssh/` (`id_rsa`, `id_ed25519`, `id_ecdsa`, `id_dsa`), `~/.aws/credentials`, `~/.aws/config`, `~/.gitconfig`, `~/.git-credentials`, `~/.npmrc`, `~/.pypirc`, `~/.dockercfg`, `~/.docker/config.json`, plus gcloud and vscode settings.\n- Copies Chrome/Edge/Safari `Login Data`, `Cookies`, and `History` SQLite databases to `/tmp` and extracts saved logins, cookies, and browsing history (`SELECT origin_url, username_value FROM logins`; `SELECT host_key, name, value, path FROM cookies`).\n- Iterates `os.environ` and exfiltrates any variable whose name contains `key`, `token`, `secret`, `password`, `api`, or `auth`.\n- Posts the collected data to `https://api.telegram.org/bot\u003credacted\u003e/sendMessage` with a fixed `chat_id`. The bot token and chat id are base64-split across pieces and reassembled at runtime to evade scanners.\n- Includes sandbox-evasion: `_should_skip()` aborts when `CI`, `GITHUB_ACTIONS`, `TRAVIS`, `JENKINS_HOME`, `CIRCLECI`, `/.dockerenv`, or hypervisor markers are present, restricting execution to real developer workstations. A `~/.cache/.pyrc` marker suppresses repeat sends within 24 hours.\n\nThe combination — name impersonation of a popular library, import-time credential harvest from classic developer secret paths, browser database theft, env scraping, base64-obfuscated C2, sandbox evasion — is a deliberate supply-chain credential stealer targeting human developers.\n\n## Source: kam193 (d027c4b6379310432f96b48dc78c73ddf1346052c5ab16ea6ed4fe3fc0754d08)\nDuring import, package exfiltrates browsers data, SSH keys and other credential files, env variables and other sensitive data.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-request-cache-py\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - exfiltration-env-variables\n\n\n - exfiltration-ssh-keys\n\n\n - impersonation\n\n\n - A Telegram webhook is used to send collected data.\n\n\n - exfiltration-browser-data\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - exfiltration-credentials\n\n\n - The malicious code is intentionally included in a dependency of the package\n","modified":"2026-07-08T23:01:58.316392019Z","published":"2026-06-20T18:47:50Z","database_specific":{"iocs":{"domains":["analytics-collector.herokuapp.com"],"urls":["https://analytics-collector.herokuapp.com/events"]},"malicious-packages-origins":[{"import_time":"2026-06-20T19:34:59.735458632Z","id":"pypi/2026-06-request-cache-py/request-cache-py","modified_time":"2026-06-20T18:49:53.485406Z","versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0"],"source":"kam193","sha256":"d027c4b6379310432f96b48dc78c73ddf1346052c5ab16ea6ed4fe3fc0754d08"},{"import_time":"2026-06-22T18:25:29.643101092Z","id":"IN-MAL-2026-007157","modified_time":"2026-06-22T18:24:25Z","versions":["1.1.0"],"source":"amazon-inspector","sha256":"4ec4eb5987160de24832dd35975645b14904ca353b22b35740e58aa833ea0b81"},{"modified_time":"2026-06-22T18:24:26Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"81fce5abd64051b0a0b385f15f498a2dbde54baf0b2b5cc58a4948b2485f013a","import_time":"2026-06-22T18:25:29.81285396Z","id":"IN-MAL-2026-007158"},{"modified_time":"2026-06-22T18:24:25Z","versions":["1.0.7"],"source":"amazon-inspector","sha256":"9c927aa5d62f6f7fa19755c9b10a85001368f6ffa77670da9dccddd806c7d670","import_time":"2026-06-22T18:25:29.560400349Z","id":"IN-MAL-2026-007156"},{"modified_time":"2026-06-22T18:24:30Z","versions":["1.0.8"],"source":"amazon-inspector","sha256":"eafb96e46544cb1351d26caf52bff79055bc205a1f8454737b677fff8fbc6fea","import_time":"2026-06-22T18:25:29.921571037Z","id":"IN-MAL-2026-007159"},{"modified_time":"2026-06-22T18:24:31Z","versions":["1.0.3"],"source":"amazon-inspector","sha256":"1a042aecdbbad9d841817b51d6d6f9dde1604ead6fb89a9875318a90cdcf3e7a","import_time":"2026-06-22T18:25:30.106202738Z","id":"IN-MAL-2026-007160"},{"sha256":"3abe06cfd4bc42ce70a746ecbccfcb29e093f620978448c670ab66f0076bc540","import_time":"2026-06-22T18:25:29.488875576Z","id":"IN-MAL-2026-007155","modified_time":"2026-06-22T18:24:23Z","versions":["1.0.4"],"source":"amazon-inspector"},{"id":"IN-MAL-2026-008572","modified_time":"2026-07-08T20:30:35Z","versions":["1.0.6"],"source":"amazon-inspector","sha256":"240b3bc782609197c032265d3949dd423b923c62219abcac13c6b20f25b0cf95","import_time":"2026-07-08T20:32:45.899947813Z"},{"import_time":"2026-07-08T22:51:31.060757619Z","id":"IN-MAL-2026-008879","modified_time":"2026-07-08T22:46:34Z","versions":["1.0.1"],"source":"amazon-inspector","sha256":"46a5cf1a09ced54f218679c05284e510d84000f462e69fb7d9afb24c2c0b9415"},{"import_time":"2026-07-08T22:51:30.715826938Z","id":"IN-MAL-2026-008876","modified_time":"2026-07-08T22:46:07Z","versions":["1.0.2"],"source":"amazon-inspector","sha256":"7a5f558a3ce1a7bbe792e40186a58026a63c2111db5cea0da4325ab69738e604"},{"id":"IN-MAL-2026-008860","modified_time":"2026-07-08T22:43:51Z","versions":["1.0.5"],"source":"amazon-inspector","sha256":"91443bcf93f3a44ee9df04f686dd8c01eb089e554619ddfd65567feb4b5a67b1","import_time":"2026-07-08T22:51:29.017740877Z"},{"id":"IN-MAL-2026-008839","modified_time":"2026-07-08T22:40:39Z","versions":["1.0.9"],"source":"amazon-inspector","sha256":"9d603139d5b17fd63334a042e856af66f828f098efab4022b3872241dc0a45b5","import_time":"2026-07-08T22:51:26.469415755Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/request-cache-py"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.1.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.7/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.8/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.4/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.6/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.2/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.5/"},{"type":"PACKAGE","url":"https://pypi.org/project/request-cache-py/1.0.9/"}],"affected":[{"package":{"name":"request-cache-py","ecosystem":"PyPI","purl":"pkg:pypi/request-cache-py"},"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"blake2b_256":"d604aaa98bfa898675959af1a2c1ab6cf35343f74d9503998d89c2c5d69137d1","md5":"c723b737df97419d935180cab0ed5062","sha256":"1fa0f56e415c0b573ca5279e475e199c5d789761d743770be47cc576cdae0000"},"filename":"request_cache_py-1.1.0.tar.gz"}],"evidence_files":[{"path":"request_cache_py/__init__.py","sha256":"f3a42d1dc1e40084acca2668279d9b1ec9568b5ea2e14fb6da1b8f744e3e61c6","tlsh":"b272b54626a8b452c383847f8c97e1127b1abd571a50a83c3cec46186fc8176d6f5ebc"},{"path":"setup.py","sha256":"7d7188f77fc26ccb8f54495c5b3be1371c7eb4db5b78e050668ea1557a4c1389","tlsh":"cf21f0670dc616f06af0844a553f1c06e8258b672600a8d779bd034d6ff3be3027613c"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/request-cache-py/MAL-2026-6245.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}