Skip to main content
AVOID.NET
← requests-secure-v2reviewed 2026-09-07 · 16 claims checked

Fact-check findings

What an automated fact-checker found when it re-read requests-secure-v2 against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

2 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #5[disputed][awaiting moderator]in the timeline
    “2024-03-26”
    reviewerThe mass typosquat upload campaign (500+ packages, 50+ requests variants) occurred on 2024-03-26.The timeline entry's date field (2024-03-26) contradicts the page's own section 2 text and both cited sources, which place the bulk upload on March 27-28, 2024. This is an internal inconsistency between the timeline and the prose describing the same event.
    Proposed correction (not yet applied)
    2024-03-27
  2. #13[disputed][awaiting moderator]in section: Ongoing Threat Landscape
    “In May 2026, Cyber Times reported the TrapDoor campaign, which targeted 34 packages across npm, PyPI, and Crates.io simultaneously, stealing SSH keys, Solana and Sui wallet keystores, AWS credentials, GitHub tokens, and browser extension data from developers.”
    reviewerIn May 2026, Cyber Times reported the TrapDoor campaign, targeting 34 packages across npm, PyPI, and Crates.io, stealing SSH keys, Solana and Sui wallet keystores, AWS credentials, GitHub tokens, and browser extension data.The 34-package scope and stolen-data details are accurate, but the outlet is misnamed as 'Cyber Times' in the prose; the correct name, used correctly elsewhere on the page (sources_used and timeline[5].source both say 'Crypto Times'), is 'Crypto Times.'
    Proposed correction (not yet applied)
    In May 2026, Crypto Times reported the TrapDoor campaign, which targeted 34 packages across npm, PyPI, and Crates.io simultaneously, stealing SSH keys, Solana and Sui wallet keystores, AWS credentials, GitHub tokens, and browser extension data from developers.

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #16[unverifiable][awaiting moderator]in section: Victim Reports and Takedown Status
    “No victim reports specifically attributing harm to requests-secure-v2 have been located in any public forum, security mailing list, GitHub issue, Reddit thread, or news article reviewed by this investigation.”
    reviewerNo victim reports specifically attributing harm to requests-secure-v2 have been located in any public forum, security mailing list, GitHub issue, Reddit thread, or news article.Consistent with this review's own searches, but a negative/absence claim of this breadth cannot be fully verified against every forum, mailing list, and GitHub issue that exists; treated as unverifiable rather than confirmed.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #11[partially supported][awaiting moderator]in section: SEO Poisoning as an Attack Vector
    “Zscaler ThreatLabz has documented black-hat SEO campaigns targeting developer searches, including searches for AI and security tools, to redirect victims to malicious download pages.”
    reviewerZscaler ThreatLabz has documented black-hat SEO campaigns targeting developer searches, including searches for AI and security tools.The cited sources support that SEO poisoning is used to distribute malware via searches for popular software (including AI tools), but neither source specifically documents targeting of 'developer searches' or 'security tools' as the page states; this is a mild overstatement/mischaracterization of what the two cited sources actually cover.

confirmed

12 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    “As of August 2026, no security researcher, vulnerability database (OSV, Vulert, Snyk), major news outlet, or PyPI record independently verifiable by this investigation has documented a package by this exact name.”
    reviewerAs of August 2026, no security researcher, vulnerability database, major news outlet, or PyPI record documents a package named requests-secure-v2.Independently re-ran the OSV query, fetched the PyPI project URL directly, and searched Snyk/security press; none surfaced a package by this exact name, consistent with the page's own hedged claim.
  2. #2[confirmed][no action needed]in section: Verification Status
    “The OSV database, which catalogues known malicious PyPI packages, returned no results for this name.”
    reviewerThe OSV database returned no results for requests-secure-v2.Directly verified via WebFetch of the cited OSV search URL.
  3. #3[confirmed][no action needed]in section: Verification Status
    “PyPI's own project listing returned an access challenge page with no matching package record.”
    reviewerPyPI's own project listing returns an access challenge page with no matching package record for requests-secure-v2.Replicated independently; the PyPI URL for this exact package slug does not resolve to a live project page.
  4. #4[confirmed][no action needed]in section: Threat Archetype: Fake requests-Impersonating PyPI Packages
    “In March 2024, security firm Checkmarx documented a campaign in which over 500 typosquatting variants of popular Python packages — including more than 50 variants specifically targeting requests, with names such as reqzests, requzsts, requyests, requesxts, and others — were uploaded to PyPI between March 27 and 28, 2024.”
    reviewerIn March 2024, Checkmarx documented over 500 typosquatting variants of popular Python packages, including 50+ targeting requests, uploaded to PyPI between March 27 and 28, 2024.Directly quoted date range matches both cited sources verbatim.
  5. #6[confirmed][no action needed]in section: Threat Archetype: Fake requests-Impersonating PyPI Packages
    “PyPI suspended new project creation on March 28, 2024 at 02:16 UTC in response, and removed the packages the same day.”
    reviewerPyPI suspended new project creation and user registration at 02:16 UTC on March 28, 2024, and removed the identified packages the same day.Timestamp and date match cited and cross-checked reporting exactly.
  6. #7[confirmed][no action needed]in section: Threat Archetype: Fake requests-Impersonating PyPI Packages
    “A separate incident documented by The Hacker News in May 2024 described a package called requests-darwin-lite, which concealed a Golang-compiled build of the Sliver command-and-control framework inside a manipulated version of the requests project logo (inflated from 300 KB to approximately 17 MB), targeting macOS systems. That package was downloaded 417 times before removal.”
    reviewerrequests-darwin-lite concealed a Golang Sliver C2 build inside a manipulated requests logo PNG inflated from 300 KB to ~17 MB, targeting macOS, downloaded 417 times before removal.All specific figures (file size, download count, framework name, targeted OS) match the cited reporting exactly.
  7. #8[confirmed][no action needed]in section: Clipboard Hijacking and Wallet Key Theft Techniques
    “The package cick on PyPI, documented by Vulert, explicitly implemented this clipboard manipulation pattern.”
    reviewerThe PyPI package cick, documented by Vulert, explicitly implemented clipboard-manipulation malware replacing crypto wallet addresses.Directly supported by the cited Vulert entry.
  8. #9[confirmed][no action needed]in section: Clipboard Hijacking and Wallet Key Theft Techniques
    “FortiGuard Labs documented a similar clipboard hijacking payload in a separate campaign involving packages such as sGMM.”
    reviewerFortiGuard Labs documented a similar clipboard-hijacking payload in a campaign involving packages such as sGMM.Package name and clipboard-hijacking mechanism confirmed in the cited FortiGuard blog.
  9. #10[confirmed][no action needed]in section: Clipboard Hijacking and Wallet Key Theft Techniques
    “ReversingLabs documented this pattern in the BIPClip campaign, and Checkmarx documented it in the AtomicDecoderss/TrustDecoderss/WalletDecoderss/ExodusDecodes campaign reported in October 2024.”
    reviewerReversingLabs documented private-key/mnemonic exfiltration in the BIPClip campaign, and Checkmarx documented it in the AtomicDecoderss/TrustDecoderss/WalletDecoderss/ExodusDecodes campaign reported in October 2024, targeting wallets including Atomic, Exodus, MetaMask, Trust Wallet, Ronin, and TronLink.Campaign names, package names, and targeted-wallet list all match cited reporting; discovery is dated late September/early October 2024, consistent with the page's 'reported in October 2024.'
  10. #12[confirmed][no action needed]in section: Ongoing Threat Landscape
    “In February 2026, The Hacker News reported that compromised dYdX npm and PyPI packages delivered wallet-stealing malware and a remote access trojan (RAT) via poisoned software updates, with 128 phantom packages accumulating over 121,000 downloads between July 2025 and January 2026.”
    reviewerIn February 2026, The Hacker News reported compromised dYdX npm and PyPI packages delivering wallet-stealing malware and a RAT, with 128 phantom packages accumulating over 121,000 downloads between July 2025 and January 2026.Figures match the cited article precisely (121,539 rounds to 'over 121,000').
  11. #14[confirmed][no action needed]in section: Ongoing Threat Landscape
    “In August 2025, The Hacker News reported that RubyGems and PyPI were hit by a wave of malicious packages stealing credentials and crypto, prompting security changes to both registries.”
    reviewerIn August 2025, The Hacker News reported RubyGems and PyPI were hit by a wave of malicious packages stealing credentials and crypto, prompting security changes to both registries.Both the RubyGems credential-theft and PyPI crypto-theft components, and the resulting registry security changes, are confirmed.
  12. #15[confirmed][no action needed]in section: Clipboard Hijacking and Wallet Key Theft Techniques
    “malicious code monitors the system clipboard for patterns matching cryptocurrency wallet addresses — including Bitcoin (bc1 prefix), Ethereum (0x prefix), Monero (4 prefix), and Litecoin (L, M, or 3 prefix) — and silently replaces any detected address with an attacker-controlled address”
    reviewerClipboard-hijacking malware pattern-matches against cryptocurrency address formats: Bitcoin (bc1 prefix), Ethereum (0x prefix), Monero (4 prefix), and Litecoin (L, M, or 3 prefix).This is standard, well-established address-format background information rather than a claim unique to one source; the prefixes described are technically accurate.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.