pypi
Malicioushelmet-fastapi@1.3.3
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 7:51 PM UTC
OSV ID
MAL-2025-191752
Ecosystem
pypi
Summary
Package contains hidden code adding a backdoor - a WebSocket path handler which will execute commands sent by an attacker knowing the path. In addition, it adds a log handler to remove related access logs. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-04-helmet-fastapi Reasons (based on the campaign): - backdoor - obfuscation
Source: kam193 (c1f805932ecbcd95197e98c6e2336eb773252abf5615fe135076d1848cb90395)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.