VYPR

pypi · Malicious package advisory

Malware

helmet-fastapi

MAL-2025-191752

Malicious code in helmet-fastapi (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c1f805932ecbcd95197e98c6e2336eb773252abf5615fe135076d1848cb90395)
Package contains hidden code adding a backdoor - a WebSocket path handler which will execute commands sent by an attacker knowing the path. In addition, it adds a log handler to remove related access logs.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-04-helmet-fastapi


Reasons (based on the campaign):


 - backdoor


 - obfuscation

Compromised versions (5)

  • 1.2
  • 1.3
  • 1.3.1
  • 1.3.2
  • 1.3.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.