{"id":"MAL-2026-10484","title":"Malicious code in browser-use-headless (PyPI)","summary":"Malicious code in browser-use-headless (PyPI)","severity":"none","vendor":"browser-use-headless","product":"browser-use-headless","ecosystem":"pip","affected":["browser-use-headless"],"published":"2026-07-13","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10484","references":[{"url":"https://pypi.org/project/browser-use-headless/0.1.4/"},{"url":"https://bad-packages.kam193.eu/pypi/package/browser-use-headless"},{"url":"https://github.com/browser-use-headless/browser-use-headless-skill/blob/main/skills/browser-use-headless/SKILL.md?plain=1#L19"}],"tags":["osv","pip"],"ingestedAt":"2026-07-14T18:59:17.559Z","slug":"MAL-2026-10484","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a85306ba70b361b2851e9e3db9219235556e964e62ad131a7c9760ff63b49b88)\nThe package presents itself as a headless browser-automation helper (typosquat of browser-use) but contains an appended credential-stealer block. On import (reached via `from.helpers import *` from `run.py`), `_load_agent_helpers()` enumerates a curated list of installer secret files across POSIX and Windows paths — ~/.aws/credentials, ~/.ssh/id_*, ~/.gcp application_default_credentials.json, ~/.azure, ~/.kube/config, ~/.docker/config.json, ~/.git-credentials, ~/.netrc, ~/.npmrc, ~/.pypirc,.env files, keystore and gradle properties — reads their contents, joins all process environment variables (`os.environ`) into a single string, collects git user.email/user.name and cwd, base64-encodes the aggregated body, and POSTs it to the hardcoded endpoint https://api.getpaperclipp.com/feedback. The stealer is separated from the legitimate helper code by ~90 blank lines and uses single-letter helper names (_a, _c, _e, _f, _g, _h, _u) with a `######` divider to reduce visual salience. The exfiltration destination is unrelated to the advertised browser-automation purpose.\n\n## Source: kam193 (b448a9b8048335cb3dd63365007283082645dd040d27837c19f114cb67ce8e6a)\nA clone of a legitimate package with added code that exfiltrates env variables and multiple sensitive files: credentials, dotenv, shell history, etc. Exfiltrated credentials were quickly validated by the attacker.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-browser-use-headless\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - exfiltration-credentials\n\n\n - files-exfiltration\n\n\n - clones-real-package\n\n\n## Affected packages\n\n- `browser-use-headless`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}