MAL-2026-17702

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/kafka-helmsman/MAL-2026-17702.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17702
Published
2026-10-08T21:15:56Z
Modified
2026-10-09T01:00:08Z
Summary
Malicious code in kafka-helmsman (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (75536e8621da28a0e941bd4a607da879a64ab71214e908992bf14840ed9a20b2)

The sdist for kafka-helmsman 99.0.5 is a dependency-confusion placeholder targeting the internal Tesla project name github.com/teslamotors/kafka-helmsman. setup.py contains no build logic; its top-level code starts a daemon thread that collects hostname, current working directory, os.uname output, a timestamp, and a UUID, then POSTs the JSON body to https://webhook.site/bf5cb178-e0cf-43b6-8b1e-fb5d2f6ea9c9 and additionally transmits the same payload to the OAST host jw1yrpkm5xpav.httpcollaborator.com both over HTTPS and via DNS lookups (nslookup/getent/dig) with a base64-url path. Because setup.py executes during pip metadata and wheel build, the beacon fires on any default pip install kafka-helmsman and on any resolver that evaluates the sdist. The package declares packages=[] and py_modules=[] and ships no functional kafka tooling, so an installer that mis-resolved the public name instead of the internal one receives only the exfiltration payload. README framing of the artifact as Bugcrowd/Tesla research does not change the behavior: installer-identifying data is sent to hardcoded third-party endpoints controlled by the author.

Source: kam193 (edc880a17d2b3a9eaeadd0a074e6debc3f507d7afbd4ac8f5c4928209fadbcde)

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

Source: ossf-package-analysis (a2d266a2b4e9df8f2466cfb34e58fe98c636cb75d4ad1ec08cee919bd9a86588)

The OpenSSF Package Analysis project identified 'kafka-helmsman' @ 99.0.1 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-10-08T21:18:09.362483578Z",
            "modified_time": "2026-10-08T21:15:56Z",
            "sha256": "a2d266a2b4e9df8f2466cfb34e58fe98c636cb75d4ad1ec08cee919bd9a86588",
            "source": "ossf-package-analysis",
            "versions": [
                "99.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021263",
            "import_time": "2026-10-08T21:42:57.408970022Z",
            "modified_time": "2026-10-08T21:23:11Z",
            "sha256": "0431384cc0de119177c0a345db1bfa2277fa4707e726176e542c0babfe1cd1f2",
            "source": "amazon-inspector",
            "versions": [
                "99.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021239",
            "import_time": "2026-10-08T21:42:55.500895338Z",
            "modified_time": "2026-10-08T21:19:45Z",
            "sha256": "a99759eb9821bcb30598eea10347dd1523ce42ec1847b9b66c5ba857ccd24785",
            "source": "amazon-inspector",
            "versions": [
                "99.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-021261",
            "import_time": "2026-10-08T21:42:57.246496983Z",
            "modified_time": "2026-10-08T21:22:52Z",
            "sha256": "d2d1d7c99040594bd5c9bb0f23a58703e1fa5f1cd15cafbe2abb3e04aa3667be",
            "source": "amazon-inspector",
            "versions": [
                "99.0.3"
            ]
        },
        {
            "id": "pypi/GENERIC-standard-pypi-install-pentest/kafka-helmsman",
            "import_time": "2026-10-08T22:18:58.155762443Z",
            "modified_time": "2026-10-08T21:36:02.265925Z",
            "sha256": "edc880a17d2b3a9eaeadd0a074e6debc3f507d7afbd4ac8f5c4928209fadbcde",
            "source": "kam193",
            "versions": [
                "99.0.1",
                "99.0.2",
                "99.0.3",
                "99.0.4",
                "99.0.5",
                "99.0.6"
            ]
        },
        {
            "id": "IN-MAL-2026-021277",
            "import_time": "2026-10-09T00:53:54.88986955Z",
            "modified_time": "2026-10-09T00:05:25Z",
            "sha256": "10f61c10a25e4aa02e6d142d652627c1e4f3033158e22d77e4bb5e96cf0562dd",
            "source": "amazon-inspector",
            "versions": [
                "99.0.4"
            ]
        },
        {
            "id": "IN-MAL-2026-021278",
            "import_time": "2026-10-09T00:53:54.955403434Z",
            "modified_time": "2026-10-09T00:05:33Z",
            "sha256": "75536e8621da28a0e941bd4a607da879a64ab71214e908992bf14840ed9a20b2",
            "source": "amazon-inspector",
            "versions": [
                "99.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-021275",
            "import_time": "2026-10-09T00:53:54.75052438Z",
            "modified_time": "2026-10-09T00:05:06Z",
            "sha256": "c52e0a7a9f07e1f3f9f17afa3bc2328c1743da9f3d81c421164c92282bc5fe92",
            "source": "amazon-inspector",
            "versions": [
                "99.0.6"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / kafka-helmsman

Package

Name
kafka-helmsman
View open source insights on deps.dev
Purl
pkg:pypi/kafka-helmsman

Affected ranges

Affected versions

99.*
99.0.1
99.0.2
99.0.3
99.0.4
99.0.5
99.0.6

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "setup.py",
            "sha256": "d4f2a3ca94be78472bbb15bad6e215cd59d0b00ecebbf4e0fc4b70b837f72e56",
            "tlsh": "2f61a783c4142c63d2c360944475e9613722790b7d036cfa7aec9395af4f47680f256e"
        }
    ],
    "package_integrity": [
        {
            "filename": "kafka_helmsman-99.0.1.tar.gz",
            "hashes": {
                "blake2b_256": "189004a13858578492254d2b8e01d434f597c5a1ed1ad619f65ac2bd082fc82b",
                "md5": "95fd10a2179b8c31d0de2cbd8913de78",
                "sha256": "8fb9ae3af1e1bba7231812809b21be6c7a9a1b07a08ee2b668c6e323ec7a2500"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/kafka-helmsman/MAL-2026-17702.json"