Malicious code in requests-auroras (PyPI)
MAL-2026-16274
Published · Modified
Dependency scanning
Check whether requests-auroras is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: kam193 (afa39517de816c01400eef99ef6ebce1357910c217c5e0ff55e4a252ea15a4c5)
During installation, package starts a reverse shell.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-requests-triwes
Reasons (based on the campaign):
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
The package overrides the install command in setup.py to execute malicious code during installation.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes