MAL-2026-11521

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/psbt-helpers/MAL-2026-11521.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11521
Published
2026-08-04T10:17:07Z
Modified
2026-08-05T08:51:26.200052100Z
Summary
Malicious code in psbt-helpers (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (82a309d768af6a39f95bb4f7c9f5d8548a95f0074613985f49f0513420dae9fa)

The code advertised as a firmware upgrader for hardware wallets in fact downloads an infostealer. The stealer searches the machine for cryptocurrency sensitive data (wallet files, seeds), browser data (passwords, cookies), all kinds of credentials (including tokens, passwords, SSH keys, TOTP seeds etc.), other sensitive files and current clipboard content. Data are exfiltrated, and the stealer configures persistence via scheduled tasks or LaunchAgent. The code deliberatly doesn't start in CI environments and checks if the system looks real.

Continuation of 2026-08-coldcard-helpers campaign. Related packages are used in malicious repository https://github.com/domaup/coldcard-poc


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-psbt-utils

Reasons (based on the campaign):

  • infostealer

  • files-exfiltration

  • clipboard-stealing

  • exfiltration-ssh-keys

  • obfuscation

  • crypto-related

  • exfiltration-cloud-tokens

  • Downloads and executes a remote malicious script.

  • exfiltration-browser-data

  • exfiltration-crypto

  • exfiltration-credentials

  • persistence

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-04T11:21:48.516301735Z",
            "modified_time": "2026-08-04T10:17:07.792559Z",
            "sha256": "394dea9d587ac1affba13c45ecfc28f5d005b2cb5f8b665dcf4591b60085a8ae",
            "source": "kam193",
            "id": "pypi/2026-08-psbt-utils/psbt-helpers",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "source": "kam193",
            "import_time": "2026-08-05T08:22:40.281729662Z",
            "sha256": "82a309d768af6a39f95bb4f7c9f5d8548a95f0074613985f49f0513420dae9fa",
            "modified_time": "2026-08-04T10:17:07.792559Z",
            "id": "pypi/2026-08-psbt-utils/psbt-helpers",
            "versions": [
                "1.0.0"
            ]
        }
    ],
    "iocs": {
        "domains": [
            "curly-violet-87a9.ricardorichp.workers.dev"
        ],
        "urls": [
            "https://curly-violet-87a9.ricardorichp.workers.dev/firmware"
        ]
    }
}
References
Credits

Affected packages

PyPI / psbt-helpers

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/psbt-helpers/MAL-2026-11521.json"