pypi

coldcard-helpers @1.4.2

Vulnerability report · Last retrieved from osv.dev August 4, 2026 at 8:52 AM UTC

Malicious

OSV ID

MAL-2026-11516

Ecosystem

pypi

Summary

When installing the package or importing the module, code starts a background task collecting sensitive data, like sensitive environment variables, private keys for cryptocurrency wallets, SSH keys, and so on to a Telegram channel. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-coldcard-helpers Reasons (based on the campaign): - exfiltration-env-variables - exfiltration-ssh-keys - exfiltration-crypto - exfiltration-credentials - uses-telegram-bot - The package overrides the install command in setup.py to execute malicious code during installation.

Source: kam193 (127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.