Logo
pypi

env-validator-tool@1.0.2

Vulnerability report · Last retrieved from osv.dev September 3, 2026 at 4:52 AM UTC

Malicious

OSV ID

MAL-2026-15828

Ecosystem

pypi

Summary

In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-telemetry-helper Reasons (based on the campaign): - exfiltration-env-variables - The malicious code is intentionally included in a dependency of the package

Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.