On August 31, 2023, The Hacker News reported that ReversingLabs had identified three more malicious packages in the VMConnect campaign: tablediter, request-plus and requestspro. The packages imitated familiar Python libraries and used behavior that could begin after installation, when an application imported and called their functions. Researchers cited infrastructure overlaps as signs of North Korean state-sponsored involvement; that evidence did not conclusively establish who operated the packages.
Which PyPI packages were malicious?
The August 31, 2023 report named three packages. tablediter mimicked the popular prettytable library, while request-plus and requestspro imitated requests. The report described them as additional packages in VMConnect, a campaign involving malicious packages designed to download an unknown second-stage payload. The Hacker News report credited ReversingLabs with the findings.
A familiar-looking name is not proof that a package is legitimate. Typosquatting relies on people choosing a lookalike rather than the intended project, so check the exact spelling and project provenance before installing.
What did the packages do?
tablediter: delayed, import-triggered activity
The report said tablediter repeatedly queried a remote server for a Base64-encoded payload. Rather than executing immediately during installation, it delayed activity until the package was imported and its functions called by an application. This can evade one common kind of behavior-based detection, though it does not make the package safe or guarantee that it will evade security tools.
The exact nature of the payload retrieved by tablediter was unknown in the 2023 report. It would be inaccurate to claim that the report identified what that second stage ultimately did.
#1 Best Overall
request-plus and requestspro: machine data and staged delivery
These packages were reported to collect information about an infected machine and send it to a command-and-control (C2) server. After a token exchange, the process led to a double-encoded Python module and a download URL. Encoding can obscure content from a casual inspection, but the report did not establish the final payload’s capabilities.
What evidence linked the campaign to North Korea?
The 2023 coverage described signs of North Korean state-sponsored involvement and cited infrastructure overlap with an npm social-engineering campaign and the June 2023 JumpCloud hack. That overlap supported the researchers’ assessment; it is not the same as proving the identity of an operator or showing definitive state direction.
The Hacker News quoted ReversingLabs security researcher Karlo Zanki saying the delayed execution raised the bar for defenders by avoiding one common form of behavior-based detection. The article also quoted him describing PyPI as a continuing malware distribution point. These are statements attributed to Zanki by The Hacker News, not a direct examination here of an original ReversingLabs report.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →How can you spot a typosquatted Python package?
Before adding a dependency, compare it with the project you intended to install. Pay particular attention to names that differ by a character, an added suffix, or a subtle change in punctuation.
- Verify the exact name. Check the package name against the intended project’s official documentation or repository rather than relying on a search result or copied command alone.
- Check the maintainer and project provenance. Look for a credible connection between the package and the project it claims to represent.
- Review release history. An unfamiliar or inconsistent history warrants extra scrutiny; a familiar name by itself is not validation.
- Review what the dependency will execute. Import-time and function-call behavior can matter, so an installation-only check may miss activity that starts later.
- Use organizational controls. Teams can review and approve dependencies and monitor endpoints for suspicious behavior. These are general defensive practices, not a guarantee that a malicious package will be detected.
How should the 2023 report be read today?
This is an incident report published August 31, 2023, not a current package-status notice. It does not establish whether the named packages are presently available, provide a validated list of indicators of compromise, or give remediation instructions for a specific version. Do not infer current registry status or treat the report as a complete incident-response guide.
Rank #3
A separate multi-government advisory dated September 18, 2026 describes WaterPlum, also called Contagious Interview, targeting IT professionals through fake job opportunities and developer-platform activity, including malicious NPM packages. That later campaign is separate: the advisory does not connect WaterPlum to VMConnect or to these PyPI package names. The Australian government’s advisory recommends endpoint detection and response monitoring as a general defensive measure in its campaign context.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

