Logo
pypi

helmet-fastapi@1.3.3

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 7:51 PM UTC

Malicious

OSV ID

MAL-2025-191752

Ecosystem

pypi

Summary

Package contains hidden code adding a backdoor - a WebSocket path handler which will execute commands sent by an attacker knowing the path. In addition, it adds a log handler to remove related access logs. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-04-helmet-fastapi Reasons (based on the campaign): - backdoor - obfuscation

Source: kam193 (c1f805932ecbcd95197e98c6e2336eb773252abf5615fe135076d1848cb90395)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.