Skip to main content
Sign in

requests-secure-v2

avoid.net/requests-secure-v20/100·20% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

requests-secure-v2 is alleged to be a malicious Python package on PyPI that impersonates the widely-used requests HTTP library through SEO poisoning, targeting cryptocurrency developers with clipboard-hijacking and wallet-key-theft payloads. As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name. The entity as named appears in no Tier 1 or Tier 2 source. The broader threat archetype it represents — typosquatted or deceptively named fake requests variants carrying crypto-stealing malware — is extensively documented and real.

Have evidence about requests-secure-v2?

Timeline(6 events)

2024-03-26

Over 500 typosquatting variants of popular Python packages including more than 50 targeting the requests library (e.g., reqzests, requzsts) were uploaded to PyPI by an automated campaign carrying zgRAT-linked crypto-stealing payloads.

Checkmarx / The Hacker News

2024-03-28

PyPI suspended new project creation and user registration at 02:16 UTC in response to the mass typosquatting campaign. All identified malicious packages were removed the same day.

The Hacker News

2024-05-01

requests-darwin-lite, a fake requests variant concealing a Golang Sliver C2 framework inside a manipulated PNG logo file, was identified on PyPI after 417 downloads and taken down. Specific date approximate based on reporting.

The Hacker News

2024-10-01

Checkmarx reported packages including AtomicDecoderss, TrustDecoderss, WalletDecoderss, and ExodusDecodes on PyPI, masquerading as wallet recovery tools to steal private keys and mnemonic phrases from Atomic, Trust Wallet, MetaMask, Exodus, and other wallets. Specific date approximate based on reporting.

The Hacker News / Checkmarx

2025-08-01

RubyGems and PyPI reported hit by further waves of malicious packages stealing credentials and cryptocurrency, prompting security changes to both registries. Specific date approximate based on reporting.

The Hacker News

2026-05-19

TrapDoor supply chain campaign detected targeting 34 packages across npm, PyPI, and Crates.io, stealing crypto wallet keystores, SSH keys, and cloud credentials from developers.

Crypto Times
Provenance & Audit Trail
15 Wayback Archives

Decision Log

  • #1publish⛓ pending8/15/2026, 5:17:57 PM
    hash: 8Bhm8DdmkbjS5aLEPaw96fbdgvZn4Q4g7gAf8hkaAhJ3

15 of 16 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/15/2026, 5:17:46 PM

last updated: 8/15/2026, 8:33:52 PM

avoid.net — verified advice for a post-truth world