requests-secure-v2
Summary
requests-secure-v2 is alleged to be a malicious Python package on PyPI that impersonates the widely-used requests HTTP library through SEO poisoning, targeting cryptocurrency developers with clipboard-hijacking and wallet-key-theft payloads. As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name. The entity as named appears in no Tier 1 or Tier 2 source. The broader threat archetype it represents — typosquatted or deceptively named fake requests variants carrying crypto-stealing malware — is extensively documented and real.
Connected Entities
1 entities · 10 linked investigationsTimeline(6 events)
2024-03-26
Over 500 typosquatting variants of popular Python packages including more than 50 targeting the requests library (e.g., reqzests, requzsts) were uploaded to PyPI by an automated campaign carrying zgRAT-linked crypto-stealing payloads.
Checkmarx / The Hacker News2024-03-28
PyPI suspended new project creation and user registration at 02:16 UTC in response to the mass typosquatting campaign. All identified malicious packages were removed the same day.
The Hacker News2024-05-01
requests-darwin-lite, a fake requests variant concealing a Golang Sliver C2 framework inside a manipulated PNG logo file, was identified on PyPI after 417 downloads and taken down. Specific date approximate based on reporting.
The Hacker News2024-10-01
Checkmarx reported packages including AtomicDecoderss, TrustDecoderss, WalletDecoderss, and ExodusDecodes on PyPI, masquerading as wallet recovery tools to steal private keys and mnemonic phrases from Atomic, Trust Wallet, MetaMask, Exodus, and other wallets. Specific date approximate based on reporting.
The Hacker News / Checkmarx2025-08-01
RubyGems and PyPI reported hit by further waves of malicious packages stealing credentials and cryptocurrency, prompting security changes to both registries. Specific date approximate based on reporting.
The Hacker News2026-05-19
TrapDoor supply chain campaign detected targeting 34 packages across npm, PyPI, and Crates.io, stealing crypto wallet keystores, SSH keys, and cloud credentials from developers.
Crypto TimesDecision Log
- #1publish⛓ pending8/15/2026, 5:17:57 PMhash: 8Bhm8DdmkbjS5aLEPaw96fbdgvZn4Q4g7gAf8hkaAhJ3
15 of 16 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/15/2026, 5:17:46 PM
last updated: 8/15/2026, 8:33:52 PM
avoid.net — verified advice for a post-truth world