VYPR

pypi · Malicious package advisory

Malware

env-validator-tool

GHSA-49jc-fj5g-832c

Malicious code in env-validator-tool (PyPI)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff)
In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-telemetry-helper


Reasons (based on the campaign):


 - exfiltration-env-variables


 - The malicious code is intentionally included in a dependency of the package

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/65028872c20a95724af35f78a4c399248291b3ce/osv/malicious/pypi/env-validator-tool/MAL-2026-15828.json))

**References:**
- https://bad-packages.kam193.eu/pypi/package/env-validator-tool
- https://github.com/ossf/malicious-packages/blob/65028872c20a95724af35f78a4c399248291b3ce/osv/malicious/pypi/env-validator-tool/MAL-2026-15828.json
- https://github.com/ossf/malicious-packages/blob/b2e6cd8bd1819c59f7afadfef27650fd124f3de2/osv/malicious/pypi/env-validator-tool/MAL-2026-15828.json
- https://pypi.org/project/env-validator-tool/1.0.0
- https://pypi.org/project/env-validator-tool/1.0.1
- https://pypi.org/project/env-validator-tool/1.0.2
- https://github.com/advisories/GHSA-49jc-fj5g-832c

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.