Skip to main content
Sign in
requests-secure-v21 decision on this page

Audit log

Every state-changing event for requests-secure-v2: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-15 17:17:57Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    8Bhm8DdmkbjS…8hkaAhJ3sha256 → base58
    verifying row…
    canonical bytes (17511 B) ▸
    {"actor":"system:backfill","investigation_id":"05607536-644a-4a27-874b-e8189103aed1","kind":"publish","page_slug":"requests-secure-v2","published_at":"2026-08-15T17:17:57.104Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"requests-secure-v2","sections":[{"content":"Extensive searches across PyPI, the OSV Open Source Vulnerabilities database, Vulert, Snyk, GitHub, Reddit, and major security news outlets (The Hacker News, BleepingComputer, The Register, Checkmarx, Unit 42, ReversingLabs, ESET, Sonatype, Datadog Security Labs) returned no records of a package named requests-secure-v2. The OSV database, which catalogues known malicious PyPI packages, returned no results for this name. PyPI's own project listing returned an access challenge page with no matching package record. No CVE, MAL advisory, GHSA entry, or journalistic account naming this specific package was located. The investigation cannot confirm the existence or former existence of requests-secure-v2 as a distinct, documented artifact. Claims about this package should be treated as unverified until a primary source — such as a PyPI advisory, security research blog post, or OSV entry — can be cited.","heading":"Verification Status","severity":"medium","sources":[{"credibility":1,"name":"OSV Open Source Vulnerabilities — PyPI search (no results for requests-secure-v2)","type":"other","url":"https://osv.dev/list?q=requests-secure-v2&ecosystem=PyPI"}]},{"content":"While requests-secure-v2 as a named artifact is unverified, the attack pattern it allegedly represents is thoroughly documented. The legitimate requests library is one of the most downloaded Python packages in existence, making it a high-value impersonation target. In March 2024, security firm Checkmarx documented a campaign in which over 500 typosquatting variants of popular Python packages — including more than 50 variants specifically targeting requests, with names such as reqzests, requzsts, requyests, requesxts, and others — were uploaded to PyPI between March 27 and 28, 2024. PyPI suspended new project creation on March 28, 2024 at 02:16 UTC in response, and removed the packages the same day. The payloads used a multi-stage infection chain: malicious code in setup.py fetched an encrypted secondary payload from a remote server, which functioned as an infostealer harvesting cryptocurrency wallets, browser cookies, browser extension data, and credentials. A persistence mechanism kept the malware active after initial execution. A separate incident documented by The Hacker News in May 2024 described a package called requests-darwin-lite, which concealed a Golang-compiled build of the Sliver command-and-control framework inside a manipulated version of the requests project logo (inflated from 300 KB to approximately 17 MB), targeting macOS systems. That package was downloaded 417 times before removal. These documented cases establish that deceptively named fake requests packages carrying crypto-targeting payloads are a real and recurring threat class, even though requests-secure-v2 specifically has not been confirmed in any public record reviewed by this investigation.","heading":"Threat Archetype: Fake requests-Impersonating PyPI Packages","severity":"high","sources":[{"credibility":2,"name":"Checkmarx: PyPI Is Under Attack — Project Creation and User Registration Suspended","type":"research","url":"https://checkmarx.com/blog/pypi-is-under-attack-project-creation-and-user-registration-suspended/"},{"credibility":2,"name":"The Hacker News: PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads","type":"news_article","url":"https://thehackernews.com/2024/03/pypi-halts-sign-ups-amid-surge-of.html"},{"credibility":2,"name":"The Hacker News: Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo","type":"news_article","url":"https://thehackernews.com/2024/05/malicious-python-package-hides-sliver.html"},{"credibility":2,"name":"Security Boulevard: PyPI Goes Quiet After Huge Malware Attack — 500+ Typosquat Fakes Found","type":"news_article","url":"https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/"}]},{"content":"Across the documented family of fake requests-impersonating and crypto-targeting PyPI packages, two primary attack techniques appear repeatedly. The first is clipboard hijacking (also called clipping or clipper malware): malicious code monitors the system clipboard for patterns matching cryptocurrency wallet addresses — including Bitcoin (bc1 prefix), Ethereum (0x prefix), Monero (4 prefix), and Litecoin (L, M, or 3 prefix) — and silently replaces any detected address with an attacker-controlled address, causing the victim to send funds to the wrong destination. The package cick on PyPI, documented by Vulert, explicitly implemented this clipboard manipulation pattern. FortiGuard Labs documented a similar clipboard hijacking payload in a separate campaign involving packages such as sGMM. The second technique is private-key and mnemonic phrase exfiltration: malicious packages masquerade as wallet recovery or management utilities and, when imported, access known local file paths used by wallets such as Atomic, Exodus, MetaMask, Trust Wallet, Ronin, and TronLink to extract seed phrases and private keys, encoding and transmitting them to attacker-controlled servers. ReversingLabs documented this pattern in the BIPClip campaign, and Checkmarx documented it in the AtomicDecoderss/TrustDecoderss/WalletDecoderss/ExodusDecodes campaign reported in October 2024. Whether requests-secure-v2 implements either technique cannot be confirmed without a verifiable package artifact.","heading":"Clipboard Hijacking and Wallet Key Theft Techniques","severity":"high","sources":[{"credibility":2,"name":"Vulert: Malicious Code in cick (PyPI) — Clipboard and Crypto Wallet Address Manipulation","type":"other","url":"https://vulert.com/vuln-db/pypi-cick-84995"},{"credibility":2,"name":"FortiGuard Labs: Info Stealing Packages Hidden in PyPI","type":"research","url":"https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi"},{"credibility":2,"name":"ReversingLabs: BIPClip — Malicious PyPI Packages Target Crypto Wallet Recovery Passwords","type":"research","url":"https://www.reversinglabs.com/blog/bipclip-malicious-pypi-packages-target-crypto-wallet-recovery-passwords"},{"credibility":2,"name":"Checkmarx: Crypto-Stealing Code Lurking in Python Package Dependencies (AtomicDecoderss et al.)","type":"research","url":"https://checkmarx.com/blog/crypto-stealing-code-lurking-in-python-package-dependencies/"},{"credibility":2,"name":"The Hacker News: PyPI Repository Found Hosting Fake Crypto Wallet Recovery Tools That Steal User Data","type":"news_article","url":"https://thehackernews.com/2024/10/pypi-repository-found-hosting-fake.html"}]},{"content":"SEO poisoning — the manipulation of search engine rankings to surface malicious results above legitimate ones — is a documented technique used to deliver malware to developers searching for popular libraries. Zscaler ThreatLabz has documented black-hat SEO campaigns targeting developer searches, including searches for AI and security tools, to redirect victims to malicious download pages. In the context of PyPI, the analogous vector is the repository's own internal search and the broader ecosystem of tutorials and Stack Overflow answers that recommend pip install commands: a fake package with a plausible name such as requests-secure or requests-secure-v2 could surface in PyPI search results or be promoted through fake documentation and tutorial sites before a developer installs it. No specific reporting confirming that requests-secure-v2 was promoted via SEO poisoning has been located by this investigation.","heading":"SEO Poisoning as an Attack Vector","severity":"medium","sources":[{"credibility":2,"name":"Zscaler ThreatLabz: Black Hat SEO Poisoning Search Engine Results for AI to Distribute Malware","type":"research","url":"https://www.zscaler.com/blogs/security-research/black-hat-seo-poisoning-search-engine-results-ai-distribute-malware"},{"credibility":2,"name":"SentinelOne: Breaking Down the SEO Poisoning Attack","type":"research","url":"https://www.sentinelone.com/blog/breaking-down-the-seo-poisoning-attack-how-attackers-are-hijacking-search-results/"}]},{"content":"No victim reports specifically attributing harm to requests-secure-v2 have been located in any public forum, security mailing list, GitHub issue, Reddit thread, or news article reviewed by this investigation. No takedown notice, PyPI removal advisory, or OSV malicious package record for this name has been found. The takedown status of requests-secure-v2 is therefore unknown: it cannot be confirmed that the package was ever published, nor that it was removed. If the package does or did exist, anyone with evidence — including a PyPI download link, pip install log, or malware sample hash — is encouraged to submit it to PyPI's security team (security@pypi.org) and to OSV.","heading":"Victim Reports and Takedown Status","severity":"low","sources":[]},{"content":"The broader threat of malicious PyPI packages targeting cryptocurrency developers has intensified in 2025 and 2026. In February 2026, The Hacker News reported that compromised dYdX npm and PyPI packages delivered wallet-stealing malware and a remote access trojan (RAT) via poisoned software updates, with 128 phantom packages accumulating over 121,000 downloads between July 2025 and January 2026. In May 2026, Cyber Times reported the TrapDoor campaign, which targeted 34 packages across npm, PyPI, and Crates.io simultaneously, stealing SSH keys, Solana and Sui wallet keystores, AWS credentials, GitHub tokens, and browser extension data from developers. In August 2025, The Hacker News reported that RubyGems and PyPI were hit by a wave of malicious packages stealing credentials and crypto, prompting security changes to both registries. These campaigns confirm that the threat archetype allegedly embodied by requests-secure-v2 remains active and evolving.","heading":"Ongoing Threat Landscape","severity":"high","sources":[{"credibility":2,"name":"The Hacker News: Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware","type":"news_article","url":"https://thehackernews.com/2026/02/compromised-dydx-npm-and-pypi-packages.html"},{"credibility":2,"name":"Crypto Times: TrapDoor Malware Hits npm, PyPI and Crates.io, Steals Crypto Wallets and SSH Keys","type":"news_article","url":"https://www.cryptotimes.io/2026/05/25/trapdoor-malware-hits-npm-pypi-crates-io-steals-crypto-wallets-ssh-keys/"},{"credibility":2,"name":"The Hacker News: RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security Changes","type":"news_article","url":"https://thehackernews.com/2025/08/rubygems-pypi-hit-by-malicious-packages.html"}]}],"sources_used":[{"credibility":1,"name":"OSV Open Source Vulnerabilities — PyPI search","type":"other","url":"https://osv.dev/list?q=requests-secure-v2&ecosystem=PyPI"},{"credibility":2,"name":"Checkmarx: PyPI Is Under Attack — Project Creation and User Registration Suspended","type":"research","url":"https://checkmarx.com/blog/pypi-is-under-attack-project-creation-and-user-registration-suspended/"},{"credibility":2,"name":"The Hacker News: PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads","type":"news_article","url":"https://thehackernews.com/2024/03/pypi-halts-sign-ups-amid-surge-of.html"},{"credibility":2,"name":"The Hacker News: Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo","type":"news_article","url":"https://thehackernews.com/2024/05/malicious-python-package-hides-sliver.html"},{"credibility":2,"name":"Security Boulevard: PyPI Goes Quiet After Huge Malware Attack — 500+ Typosquat Fakes Found","type":"news_article","url":"https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/"},{"credibility":2,"name":"Vulert: Malicious Code in cick (PyPI) — Clipboard and Crypto Wallet Address Manipulation","type":"other","url":"https://vulert.com/vuln-db/pypi-cick-84995"},{"credibility":2,"name":"FortiGuard Labs: Info Stealing Packages Hidden in PyPI","type":"research","url":"https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi"},{"credibility":2,"name":"ReversingLabs: BIPClip — Malicious PyPI Packages Target Crypto Wallet Recovery Passwords","type":"research","url":"https://www.reversinglabs.com/blog/bipclip-malicious-pypi-packages-target-crypto-wallet-recovery-passwords"},{"credibility":2,"name":"Checkmarx: Crypto-Stealing Code Lurking in Python Package Dependencies","type":"research","url":"https://checkmarx.com/blog/crypto-stealing-code-lurking-in-python-package-dependencies/"},{"credibility":2,"name":"The Hacker News: PyPI Repository Found Hosting Fake Crypto Wallet Recovery Tools That Steal User Data","type":"news_article","url":"https://thehackernews.com/2024/10/pypi-repository-found-hosting-fake.html"},{"credibility":2,"name":"Zscaler ThreatLabz: Black Hat SEO Poisoning Search Engine Results for AI to Distribute Malware","type":"research","url":"https://www.zscaler.com/blogs/security-research/black-hat-seo-poisoning-search-engine-results-ai-distribute-malware"},{"credibility":2,"name":"SentinelOne: Breaking Down the SEO Poisoning Attack","type":"research","url":"https://www.sentinelone.com/blog/breaking-down-the-seo-poisoning-attack-how-attackers-are-hijacking-search-results/"},{"credibility":2,"name":"The Hacker News: Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware","type":"news_article","url":"https://thehackernews.com/2026/02/compromised-dydx-npm-and-pypi-packages.html"},{"credibility":2,"name":"Crypto Times: TrapDoor Malware Hits npm, PyPI and Crates.io, Steals Crypto Wallets and SSH Keys","type":"news_article","url":"https://www.cryptotimes.io/2026/05/25/trapdoor-malware-hits-npm-pypi-crates-io-steals-crypto-wallets-ssh-keys/"},{"credibility":2,"name":"The Hacker News: RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security Changes","type":"news_article","url":"https://thehackernews.com/2025/08/rubygems-pypi-hit-by-malicious-packages.html"},{"credibility":2,"name":"Unit 42 Palo Alto Networks: Six Malicious Python Packages in the PyPI Targeting Windows Users","type":"research","url":"https://unit42.paloaltonetworks.com/malicious-packages-in-pypi/"}],"summary":"requests-secure-v2 is alleged to be a malicious Python package on PyPI that impersonates the widely-used requests HTTP library through SEO poisoning, targeting cryptocurrency developers with clipboard-hijacking and wallet-key-theft payloads. As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name. The entity as named appears in no Tier 1 or Tier 2 source. The broader threat archetype it represents — typosquatted or deceptively named fake requests variants carrying crypto-stealing malware — is extensively documented and real.","timeline":[{"date":"2024-03-26","event":"Over 500 typosquatting variants of popular Python packages including more than 50 targeting the requests library (e.g., reqzests, requzsts) were uploaded to PyPI by an automated campaign carrying zgRAT-linked crypto-stealing payloads.","source":"Checkmarx / The Hacker News","source_url":"https://checkmarx.com/blog/pypi-is-under-attack-project-creation-and-user-registration-suspended/"},{"date":"2024-03-28","event":"PyPI suspended new project creation and user registration at 02:16 UTC in response to the mass typosquatting campaign. All identified malicious packages were removed the same day.","source":"The Hacker News","source_url":"https://thehackernews.com/2024/03/pypi-halts-sign-ups-amid-surge-of.html"},{"date":"2024-05-01","event":"requests-darwin-lite, a fake requests variant concealing a Golang Sliver C2 framework inside a manipulated PNG logo file, was identified on PyPI after 417 downloads and taken down. Specific date approximate based on reporting.","source":"The Hacker News","source_url":"https://thehackernews.com/2024/05/malicious-python-package-hides-sliver.html"},{"date":"2024-10-01","event":"Checkmarx reported packages including AtomicDecoderss, TrustDecoderss, WalletDecoderss, and ExodusDecodes on PyPI, masquerading as wallet recovery tools to steal private keys and mnemonic phrases from Atomic, Trust Wallet, MetaMask, Exodus, and other wallets. Specific date approximate based on reporting.","source":"The Hacker News / Checkmarx","source_url":"https://thehackernews.com/2024/10/pypi-repository-found-hosting-fake.html"},{"date":"2025-08-01","event":"RubyGems and PyPI reported hit by further waves of malicious packages stealing credentials and cryptocurrency, prompting security changes to both registries. Specific date approximate based on reporting.","source":"The Hacker News","source_url":"https://thehackernews.com/2025/08/rubygems-pypi-hit-by-malicious-packages.html"},{"date":"2026-05-19","event":"TrapDoor supply chain campaign detected targeting 34 packages across npm, PyPI, and Crates.io, stealing crypto wallet keystores, SSH keys, and cloud credentials from developers.","source":"Crypto Times","source_url":"https://www.cryptotimes.io/2026/05/25/trapdoor-malware-hits-npm-pypi-crates-io-steals-crypto-wallets-ssh-keys/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 68ef5702-64cf-4082-9598-2f1b261d25dc
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.