Malicious code in request-cache-py (PyPI)
The request-cache-py package on PyPI is a malicious library impersonating the legitimate requests-cache library. Upon import, it starts a background thread that harvests sensitive installer-side secrets including SSH private keys, AWS credentials, Git credentials, npm and Docker config files, and browser data such as saved logins, cookies, and history. It also collects environment variables containing sensitive keywords and exfiltrates all this data to a hardcoded Telegram bot. The package includes sandbox evasion techniques to avoid detection in CI environments and prevents repeated data exfiltration within 24 hours. This is a deliberate supply-chain credential stealer targeting developer workstations.
AI Analysis
Technical Summary
request-cache-py is a malicious PyPI package that impersonates the popular requests-cache library. On import, it executes code that reads private keys and credentials from common developer secret locations (e.g., ~/.ssh/, ~/.aws/, ~/.gitconfig), extracts browser login data, cookies, and history from Chrome, Edge, and Safari SQLite databases, and collects environment variables containing sensitive keywords. The stolen data is exfiltrated via a Telegram bot webhook with the bot token and chat ID obfuscated using base64 splitting. The package includes sandbox evasion to avoid execution in CI or containerized environments and suppresses repeated exfiltration within 24 hours using a local marker file. This malicious code is embedded directly in the package, making it a supply-chain threat targeting human developers.
Potential Impact
Successful import of this package leads to the theft of a wide range of sensitive credentials and secrets from the developer's environment, including SSH private keys, cloud credentials, Git credentials, npm and Docker configuration files, browser saved logins and cookies, and environment variables containing secrets. This can result in unauthorized access to source code repositories, cloud resources, developer accounts, and other sensitive systems. The exfiltration to a Telegram bot provides attackers with direct access to stolen secrets, enabling further compromise. The sandbox evasion reduces the chance of detection during automated analysis, increasing the risk of prolonged undetected compromise.
Mitigation Recommendations
No official patch or remediation is indicated in the provided data. Users should immediately stop using the request-cache-py package and remove it from their environments. Verify that no sensitive credentials have been compromised and rotate any potentially exposed secrets, including SSH keys, cloud credentials, and API tokens. Use only verified and trusted packages from official sources, and consider implementing supply-chain security measures such as package signing and dependency auditing. Monitor for any suspicious activity related to exposed credentials. Patch status is not yet confirmed — check the vendor advisory or PyPI security advisories for current remediation guidance.
Malicious code in request-cache-py (PyPI)
Description
The request-cache-py package on PyPI is a malicious library impersonating the legitimate requests-cache library. Upon import, it starts a background thread that harvests sensitive installer-side secrets including SSH private keys, AWS credentials, Git credentials, npm and Docker config files, and browser data such as saved logins, cookies, and history. It also collects environment variables containing sensitive keywords and exfiltrates all this data to a hardcoded Telegram bot. The package includes sandbox evasion techniques to avoid detection in CI environments and prevents repeated data exfiltration within 24 hours. This is a deliberate supply-chain credential stealer targeting developer workstations.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
request-cache-py is a malicious PyPI package that impersonates the popular requests-cache library. On import, it executes code that reads private keys and credentials from common developer secret locations (e.g., ~/.ssh/, ~/.aws/, ~/.gitconfig), extracts browser login data, cookies, and history from Chrome, Edge, and Safari SQLite databases, and collects environment variables containing sensitive keywords. The stolen data is exfiltrated via a Telegram bot webhook with the bot token and chat ID obfuscated using base64 splitting. The package includes sandbox evasion to avoid execution in CI or containerized environments and suppresses repeated exfiltration within 24 hours using a local marker file. This malicious code is embedded directly in the package, making it a supply-chain threat targeting human developers.
Potential Impact
Successful import of this package leads to the theft of a wide range of sensitive credentials and secrets from the developer's environment, including SSH private keys, cloud credentials, Git credentials, npm and Docker configuration files, browser saved logins and cookies, and environment variables containing secrets. This can result in unauthorized access to source code repositories, cloud resources, developer accounts, and other sensitive systems. The exfiltration to a Telegram bot provides attackers with direct access to stolen secrets, enabling further compromise. The sandbox evasion reduces the chance of detection during automated analysis, increasing the risk of prolonged undetected compromise.
Mitigation Recommendations
No official patch or remediation is indicated in the provided data. Users should immediately stop using the request-cache-py package and remove it from their environments. Verify that no sensitive credentials have been compromised and rotate any potentially exposed secrets, including SSH keys, cloud credentials, and API tokens. Use only verified and trusted packages from official sources, and consider implementing supply-chain security measures such as package signing and dependency auditing. Monitor for any suspicious activity related to exposed credentials. Patch status is not yet confirmed — check the vendor advisory or PyPI security advisories for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6245
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4f6c5f68715ace4315a019
Added to database: 07/09/2026, 09:39:43 UTC
Last enriched: 07/09/2026, 10:03:20 UTC
Last updated: 07/19/2026, 00:37:05 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.