🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

flasq

Package Overview
Dependencies
Maintainers
1
Versions
4
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
This package has been flagged as malicious. It is considered unsafe regardless of version.

This setup script is a high-confidence malicious supply-chain dropper. It overrides the setuptools install step to base64-decode and exec embedded code during package installation on Linux. The executed payload then downloads additional content from a hardcoded remote URL, stages it in a temporary location, marks it executable, and runs it via subprocess—behavior incompatible with a benign HTTP client utility.

flasq

HTTP client utilities

pipPyPI
Version
0.3.0
Weekly downloads
0
Maintainers
1
Weekly downloads
 
Created

requestss

Lightweight HTTP helpers (compat shim).

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts