Malicious code in env-validator-tool (PyPI)
Malware
Published
Sep 3, 2026
to the GitHub Advisory Database
•
Updated Sep 4, 2026
Description
Published to the GitHub Advisory Database
Sep 3, 2026
Reviewed
Sep 3, 2026
Last updated
Sep 4, 2026
Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff)
In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-telemetry-helper
Reasons (based on the campaign):
exfiltration-env-variables
The malicious code is intentionally included in a dependency of the package
Credit: OpenSSF (source)
References