Vulnerability MAL-2026-17191

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 day ago
September 26, 2026 at 10:49 PM UTC
Malicious code in requests-cache-utils (PyPI)
1.0.0
1.0.0

Summary

Malicious code in requests-cache-utils (PyPI)

Details

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-requests-cache-utils

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • Downloads and executes a remote executable.

  • malware

  • infostealer

  • exfiltration-browser-data

Impacted packages

Timeline

Published
1 day ago
September 26, 2026 at 10:49 PM UTC
Last Modified
1 day ago
September 26, 2026 at 11:30 PM UTC