pypi · Malicious package advisory
Malwareenv-validator-tool
GHSA-49jc-fj5g-832c
Malicious code in env-validator-tool (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff) In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-telemetry-helper Reasons (based on the campaign): - exfiltration-env-variables - The malicious code is intentionally included in a dependency of the package --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/65028872c20a95724af35f78a4c399248291b3ce/osv/malicious/pypi/env-validator-tool/MAL-2026-15828.json)) **References:** - https://bad-packages.kam193.eu/pypi/package/env-validator-tool - https://github.com/ossf/malicious-packages/blob/65028872c20a95724af35f78a4c399248291b3ce/osv/malicious/pypi/env-validator-tool/MAL-2026-15828.json - https://github.com/ossf/malicious-packages/blob/b2e6cd8bd1819c59f7afadfef27650fd124f3de2/osv/malicious/pypi/env-validator-tool/MAL-2026-15828.json - https://pypi.org/project/env-validator-tool/1.0.0 - https://pypi.org/project/env-validator-tool/1.0.1 - https://pypi.org/project/env-validator-tool/1.0.2 - https://github.com/advisories/GHSA-49jc-fj5g-832c
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.