env-validator-tool@1.0.2
Vulnerability report · Last retrieved from osv.dev September 3, 2026 at 4:52 AM UTC
OSV ID
MAL-2026-15828
Ecosystem
pypi
Summary
In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-telemetry-helper Reasons (based on the campaign): - exfiltration-env-variables - The malicious code is intentionally included in a dependency of the package
Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.