{"id":"MAL-2026-11413","title":"Malicious code in reguestsc (PyPI)","summary":"Malicious code in reguestsc (PyPI)","severity":"none","vendor":"reguestsc","product":"reguestsc","ecosystem":"pip","affected":["reguestsc"],"published":"2026-07-31","updated":"2026-07-31","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-11413","references":[{"url":"https://www.virustotal.com/gui/file/db86ed61afec83acb523e8b00558ee7641b2ddc388d542dc0ff2922625da013f/detection"},{"url":"https://tria.ge/260731-kqvw2aff97/behavioral1"},{"url":"https://app.any.run/tasks/348751a8-657c-4a3d-bee1-dedae5264036"},{"url":"https://bad-packages.kam193.eu/pypi/package/reguestsc"}],"tags":["osv","pip"],"ingestedAt":"2026-07-31T19:10:07.365Z","slug":"MAL-2026-11413","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (20e4ae2ce79408a65e9b4bb348c2d69e20eb6072e3641531e2ec5773f1bbddd6)\nClones of a legitimate library with injected code downloading and executing a malicious executable on import. Dynamic analysis identified it as salatstealer.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-reguestsc\n\n\nReasons (based on the campaign):\n\n\n - typosquatting\n\n\n - Downloads and executes a remote executable.\n\n\n - malware\n\n\n - clones-real-package\n\n\n - spyware-like\n\n\n - infostealer\n\n\n## Affected packages\n\n- `reguestsc`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}