coldcard-helpers @1.4.2
Vulnerability report · Last retrieved from osv.dev August 4, 2026 at 8:52 AM UTC
OSV ID
MAL-2026-11516
Ecosystem
pypi
Summary
When installing the package or importing the module, code starts a background task collecting sensitive data, like sensitive environment variables, private keys for cryptocurrency wallets, SSH keys, and so on to a Telegram channel. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-coldcard-helpers Reasons (based on the campaign): - exfiltration-env-variables - exfiltration-ssh-keys - exfiltration-crypto - exfiltration-credentials - uses-telegram-bot - The package overrides the install command in setup.py to execute malicious code during installation.
Source: kam193 (127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.