MAL-2026-15829

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telemetry-helper/MAL-2026-15829.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-15829
Published
2026-09-03T00:43:22Z
Modified
2026-09-03T01:45:05.404352815Z
Summary
Malicious code in telemetry-helper (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (26ef1779c00c37e2ee65632fefde6bbe242f5a15294ee018caa1d1d2ad5b6000)

On import telemetry_helper, top-level code starts a daemon thread that sleeps 30 seconds and then POSTs a JSON payload containing the hostname, username, current working directory, and the entire process environment (dict(os.environ)) to a hardcoded webhook.site inbox at https://webhook.site/e32d3b8a-a5df-40cc-ae60-7a8343b581e4. os.environ on developer and CI hosts routinely contains credential-grade variables (AWSACCESSKEYID / AWSSECRETACCESSKEY, GITHUBTOKEN, NPMTOKEN, PYPITOKEN / TWINEPASSWORD, database URLs, private keys), so this is a bulk credential and host-identity harvester. The destination is an anonymous third-party webhook inbox unrelated to any declared publisher, and the 30-second delay before the POST is consistent with evasion of short-lived install/import sandboxes. The behavior fires unconditionally at import with no opt-out and no relation to any advertised functionality.

Source: kam193 (f1bdc82cf3a04a5e654f400c53ec66cdbdd1c8ad0709c37eb653ab2eac4830db)

In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-telemetry-helper

Reasons (based on the campaign):

  • exfiltration-env-variables

  • The malicious code is intentionally included in a dependency of the package

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-09-03T01:33:33.320944394Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ],
            "id": "IN-MAL-2026-019356",
            "modified_time": "2026-09-03T01:31:34Z",
            "sha256": "26ef1779c00c37e2ee65632fefde6bbe242f5a15294ee018caa1d1d2ad5b6000"
        },
        {
            "import_time": "2026-09-03T01:33:33.577537578Z",
            "source": "amazon-inspector",
            "versions": [
                "2.0.0"
            ],
            "id": "IN-MAL-2026-019359",
            "modified_time": "2026-09-03T01:32:00Z",
            "sha256": "9306ddc3944d54d3b469810fab5115bc570cf9378187e31adb5d40f324641a62"
        },
        {
            "import_time": "2026-09-03T01:33:33.732023255Z",
            "id": "IN-MAL-2026-019360",
            "versions": [
                "1.1.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-09-03T01:32:08Z",
            "sha256": "bde8d8019a5c42631f81583549be7e8289adc08e1ecbc33f5c9189ad5a998cee"
        },
        {
            "import_time": "2026-09-03T01:33:35.71373856Z",
            "id": "pypi/2026-09-telemetry-helper/telemetry-helper",
            "versions": [
                "1.0.0",
                "1.0.1",
                "1.0.2",
                "1.1.0",
                "1.2.0",
                "1.3.0",
                "2.0.0",
                "2.0.1"
            ],
            "source": "kam193",
            "modified_time": "2026-09-03T00:43:22.851497Z",
            "sha256": "f1bdc82cf3a04a5e654f400c53ec66cdbdd1c8ad0709c37eb653ab2eac4830db"
        },
        {
            "import_time": "2026-09-03T01:33:33.134368071Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ],
            "id": "IN-MAL-2026-019355",
            "modified_time": "2026-09-03T01:31:26Z",
            "sha256": "39aade3885deec2e783f150f75c98b4e0277cb5b75bb75143db5e14d1b48a483"
        },
        {
            "import_time": "2026-09-03T01:33:33.406880282Z",
            "source": "amazon-inspector",
            "versions": [
                "2.0.1"
            ],
            "id": "IN-MAL-2026-019357",
            "modified_time": "2026-09-03T01:31:43Z",
            "sha256": "4d4c31bb3d049c649bfd311ae9c2eacc467dc99fc5f9327af455a882c72daead"
        },
        {
            "import_time": "2026-09-03T01:33:33.511613246Z",
            "source": "amazon-inspector",
            "versions": [
                "1.3.0"
            ],
            "id": "IN-MAL-2026-019358",
            "modified_time": "2026-09-03T01:31:50Z",
            "sha256": "5743abd7e4da41f524cf146db67e23cd811a7b6011dcf87ed5328de25177ed97"
        },
        {
            "import_time": "2026-09-03T01:33:33.783684189Z",
            "id": "IN-MAL-2026-019361",
            "versions": [
                "1.2.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-09-03T01:32:18Z",
            "sha256": "703cb7e62c7717fb5215d65455554d0dffc2d9471b8c25ed5d446c989ce86953"
        },
        {
            "import_time": "2026-09-03T01:33:33.838073707Z",
            "id": "IN-MAL-2026-019362",
            "versions": [
                "1.0.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-09-03T01:32:25Z",
            "sha256": "80946bf96b3cc2009e05cf4371b44db249858cfe78fdd7ff033862dd1a88ca44"
        }
    ],
    "iocs": {
        "urls": [
            "https://real-router.duckdns.org/collect"
        ],
        "domains": [
            "real-router.duckdns.org"
        ]
    }
}
References
Credits

Affected packages

PyPI / telemetry-helper

Package

Name
telemetry-helper
View open source insights on deps.dev
Purl
pkg:pypi/telemetry-helper

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
2.*
2.0.0
2.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/telemetry-helper/MAL-2026-15829.json"
indicators
{
    "evidence_files": [
        {
            "path": "telemetry_helper/__init__.py",
            "tlsh": "65f005d29ea820885745e7d81a2572642313fd1b2f117c24fc7c97301f8e20700f03b5",
            "sha256": "75112ad48c3d9a0510aadc61e6a17b1cd006c11724bf8cb062bc0f8701a79845"
        }
    ],
    "package_integrity": [
        {
            "filename": "telemetry_helper-1.0.1-py3-none-any.whl",
            "hashes": {
                "sha256": "303cec7ac68de4030b1f10c40bb64300ddeba44255e2627a6fe6c39b8429448c",
                "blake2b_256": "efafb965111adc1c0860fa50ae2f5366c41aae0ccc46c6c2ba2758f467a38637",
                "md5": "d8f58d8fd7bb82dc25afa7d6cb38aa3c"
            }
        },
        {
            "filename": "telemetry_helper-1.0.1.tar.gz",
            "hashes": {
                "sha256": "cf379a3a5bc383ed96d669c468ff17272d060d8aecade58d35164543c9486d8a",
                "blake2b_256": "93bb56ff6d4d1ff234e60a45859bd3b9e986d111ea2d7f93dd7da0745270b417",
                "md5": "695751bb965b3951188c92e4de5c30af"
            }
        }
    ]
}
cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code"
    }
]