Malware & Info-Stealers 2022 Incident #37

requesys ransomware

Estimated Financial Impact
File encryption on Windows
Blast Radius
Actual ransomware on PyPI

What Happened

A typosquat of the popular requests Python package containing actual ransomware that encrypted files on Windows systems. One of the most destructive PyPI malware payloads discovered, crossing the line from credential theft to full file destruction.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCHPACKAGE_ACTIVE_MALWARE

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Sonatype (Nexus) Caught Nexus Firewall blocks known-malicious packages at ingestion
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← Cool Package / pytoileur pymafka Cobalt Strike →