Attackers compromised the GitHub account of the Deep-Live-Cam maintainer, reportedly despite two-factor authentication, and modified the face-swapping project's requirements.txt to replace the legitimate requests dependency with the attacker-controlled pypls/requests repository. The malicious dependency used obfuscated build-time code in setup.py to retrieve a multistage Python payload during pip/setuptools installation; the malicious revision was present on the main branch for about 9 hours and 39 minutes before it was reverted.
The payload targeted Windows and macOS, established per-user startup persistence, and monitored the clipboard for supported cryptocurrency wallet addresses, replacing them with attacker-controlled addresses to redirect payments. Deep-Live-Cam has roughly 96,600 GitHub stars, increasing potential downstream exposure, though available evidence confirms the malware's execution path and capabilities—not the number of infected users, successful thefts, financial losses, or attacker attribution.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
SafeDep published an analysis documenting the malicious dependency, staged Windows/macOS payload delivery, clipboard-hijacking behavior, persistence mechanisms, and related infrastructure. The analysis noted that available evidence did not establish infection volume, attacker attribution, theft, or financial losses.
Deep-Live-Cam reverted the malicious dependency change with commit 55d306d5ae07a4e6494013422ab244306a5c0879 at 01:37:35 UTC. The malicious revision had remained on the main branch for approximately 9 hours and 39 minutes.
GitHub user fred-cardoso opened Deep-Live-Cam issue #1930 identifying the malicious dependency at 01:26:18 UTC.
Installing the altered dependency caused an obfuscated setup.py to execute during pip/setuptools source builds, retrieve further code for Windows and macOS, establish startup persistence, and monitor the clipboard for cryptocurrency addresses to replace with attacker-controlled addresses.
A commit pushed under the hacksider account modified Deep-Live-Cam's requirements.txt, rewriting 18 dependency entries and adding requests from the attacker-controlled pypls/requests Git repository. The commit was pushed at 15:58:54 UTC.
The GitHub account pypls and its repository impersonating the Requests package were created. The repository declared its package name as requests while retaining metadata linked to the legitimate project.
The Deep-Live-Cam maintainer reported unusual account access despite two-factor authentication and changed passwords and keys following the incident. Available unsigned commit metadata did not establish whether a token, SSH key, or authenticated session had been compromised.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesafedep.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.