kdewebhelper @1.5.0
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 10:32 AM UTC
OSV ID
MAL-2025-191772
Ecosystem
pypi
Summary
Importing the module connects to a Telegram bot and provides its operator with abilities to execute commands, exfiltrate and encrypt data. The target group seems to be KDE developers, according to the package description --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-11-kdewebhelper Reasons (based on the campaign): - exfiltration-generic - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine. - exfiltration-credentials - rat
Source: kam193 (da8701a407522875f63d2aaa28d27194fe8e2faa4d7782fd66639f224ae62dcd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.