Skip to main content

Malicious code in httpz-requests (PyPI)

0
Critical
Published: 08/18/2026 (08/18/2026, 19:24:17 UTC)
Source: GCVE Database
Product: httpz-requests

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (004770b4da0c6705f95ef2c8654fd81d37650ffacaad7160041bded02cdb7fbc) httpz-requests exposes a Telegram bot (`start_bot`, `run_cmd_enc`, `http_request`) whose message handler executes arbitrary shell commands on the host running the package, granting a remote Telegram operator full command execution under the installer's user account. Documented remote commands include arbitrary shell execution (`chalao`, `.sh <command>`, `.py <file>`, `.exec <file>`), destructive filesystem operations (`rm -rf <path>`), single- and bulk-file exfiltration (`take <file>`, `take all`), a full-host backup mode that produces split 50MB archives with `.partNNN` chunking (`get all`), and environment-variable dumping (`.printenv`) — collectively enabling remote theft of filesystem contents and process-environment secrets (cloud, CI, and API credentials). The package is shipped only as compiled Cython `.so` files with no Python source, and self-describes obfuscation features that XOR+base64-encode command strings and disguise execution as `http_request("POST",...)` so plaintext commands do not appear in `ps` or system logs; the Telegram bot token is stored encoded and decoded at runtime by `dec()`. The distribution name `httpz-requests` and import name `httpz_requests` resemble the top-100 PyPI package `requests` while presenting a Telegram remote-shell API instead of an HTTP client, and metadata is unfilled boilerplate (author `Aapka Naam <[email protected]>`, homepage `https://github.com/YOUR_GITHUB_USERNAME/httpz-requests`). ## Source: kam193 (38eff923106836997e28de6d7173a1553da126be230b341fe64f0c4c215769a2) The package provides Telegram-based remote access to the machine it runs on. It was deliberately created and used to hack other machines, exfiltrate files and credentials. This package automatically ensures persistence and starts a malicious process on import. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-httpz-requests Reasons (based on the campaign): - files-exfiltration - rat - persistence - uses-telegram-bot - obfuscation - native-extension

Affected software

PyPIghsa
httpz-requests
Affected versions
=1.8.0=1.9.0=1.10.0=1.11.0=1.12.0=1.13.0=1.14.0=1.15.0=1.16.0=1.17.0=1.18.0=1.19.0=1.20.0=1.21.0=1.21.1=1.21.2=1.21.3=1.21.4=1.21.5=1.21.6=1.21.7=1.21.8=1.21.9=1.21.10=1.21.11=1.21.12=1.21.13=1.21.14=1.21.15=1.21.16=1.21.17=1.21.18=1.21.19=1.21.20

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 00:51:08 UTC

Technical Analysis

httpz-requests is a malicious PyPI package that exposes a Telegram bot allowing remote operators to execute arbitrary shell commands on the host system under the installer's user account. The bot supports commands for executing shell scripts, deleting files, exfiltrating single or multiple files, creating full-host backups in split archives, and dumping environment variables. The package is shipped as obfuscated compiled Cython .so files, with command strings XOR+base64 encoded and disguised as HTTP requests to evade detection in process listings and logs. The Telegram bot token is stored encoded and decoded at runtime. The package name and import name closely resemble the popular requests package to deceive users. It automatically ensures persistence and starts malicious processes upon import, facilitating remote access and data theft.

Potential Impact

This malicious package grants remote attackers full command execution on the host machine under the installing user's privileges. It enables theft of filesystem contents, environment variables, and sensitive credentials, potentially compromising cloud and CI environments. The persistence mechanism allows continued unauthorized access. The obfuscation and disguise techniques hinder detection and forensic analysis. Overall, it poses a severe risk of data exfiltration, system compromise, and credential theft.

Mitigation Recommendations

This package is inherently malicious and should be removed immediately if found in any environment. Users should avoid installing packages with suspicious or misleading names, especially those resembling popular libraries. There is no official patch or fix since this is a malicious package rather than a vulnerability in legitimate software. Security teams should audit installed packages, verify package provenance, and consider blocking or monitoring PyPI packages with similar suspicious characteristics. Use trusted sources and verify package integrity before installation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14130
Osv Schema Version
1.7.4
Ecosystems
["PyPI"]

Threat ID: 6a84fa65c6e8be0332ef1305

Added to database: 08/19/2026, 00:35:49 UTC

Last enriched: 08/19/2026, 00:51:08 UTC

Last updated: 10/03/2026, 19:29:18 UTC

Views: 61

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses