Skip to main content
AVOID.NET

requests-secure-v2

avoid.net/requests-secure-v2→0/100·20% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5PMwgw…Ge3W

Summary

requests-secure-v2 is alleged to be a malicious Python package on PyPI that impersonates the widely-used requests HTTP library through SEO poisoning, targeting cryptocurrency developers with clipboard-hijacking and wallet-key-theft payloads. As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name. The entity as named appears in no Tier 1 or Tier 2 source. The broader threat archetype it represents — typosquatted or deceptively named fake requests variants carrying crypto-stealing malware — is extensively documented and real.

Connected Entities

9 entities · 59 linked investigations
Organizations
□Ronin Bridge52□Ethereum64□Trust Wallet□requests-secure-v2□Solana□Sui□Monero
Tokens
♦Bitcoin♦Litecoin
Relationships
  • Ronin Bridge→mentioned with→Ethereum(80%)
  • Ethereum→mentioned with→Bitcoin(60%)
  • Monero→mentioned with→Bitcoin(60%)
  • Litecoin→mentioned with→Bitcoin(70%)
  • Litecoin→mentioned with→Monero(65%)
  • Trust Wallet→mentioned with→Bitcoin(60%)
  • Trust Wallet→mentioned with→Ethereum(75%)
  • Sui→mentioned with→Ethereum(70%)
  • requests-secure-v2→mentioned with→Trust Wallet(80%)
  • requests-secure-v2→mentioned with→Bitcoin(60%)
  • + 7 more
Have evidence about requests-secure-v2?

Timeline(6 events)

26 March 2024

Over 500 typosquatting variants of popular Python packages including more than 50 targeting the requests library (e.g., reqzests, requzsts) were uploaded to PyPI by an automated campaign carrying zgRAT-linked crypto-stealing payloads.

Checkmarx / The Hacker News

28 March 2024

PyPI suspended new project creation and user registration at 02:16 UTC in response to the mass typosquatting campaign. All identified malicious packages were removed the same day.

The Hacker News

May 2024

requests-darwin-lite, a fake requests variant concealing a Golang Sliver C2 framework inside a manipulated PNG logo file, was identified on PyPI after 417 downloads and taken down. Specific date approximate based on reporting.

The Hacker News

October 2024

Checkmarx reported packages including AtomicDecoderss, TrustDecoderss, WalletDecoderss, and ExodusDecodes on PyPI, masquerading as wallet recovery tools to steal private keys and mnemonic phrases from Atomic, Trust Wallet, MetaMask, Exodus, and other wallets. Specific date approximate based on reporting.

The Hacker News / Checkmarx

August 2025

RubyGems and PyPI reported hit by further waves of malicious packages stealing credentials and cryptocurrency, prompting security changes to both registries. Specific date approximate based on reporting.

The Hacker News

19 May 2026

TrapDoor supply chain campaign detected targeting 34 packages across npm, PyPI, and Crates.io, stealing crypto wallet keystores, SSH keys, and cloud credentials from developers.

Crypto Times
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 15 of 16 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0716 claims checked2 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 8/15/2026, 5:17:46 PM

last updated: 8/25/2026, 1:35:04 PM

6 views

avoid.net — verified advice for a post-truth world