{"id":"MAL-2026-17702","title":"Malicious code in kafka-helmsman (PyPI)","summary":"Malicious code in kafka-helmsman (PyPI)","severity":"critical","exploited":true,"vendor":"kafka-helmsman","product":"kafka-helmsman","ecosystem":"pip","affected":["kafka-helmsman"],"published":"2026-10-08","updated":"2026-10-09","sourceUpdated":"2026-10-09T01:00:08.497849713Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17702","references":[{"url":"https://pypi.org/project/kafka-helmsman/99.0.1/"},{"url":"https://pypi.org/project/kafka-helmsman/99.0.2/"},{"url":"https://pypi.org/project/kafka-helmsman/99.0.3/"},{"url":"https://bad-packages.kam193.eu/pypi/package/kafka-helmsman"},{"url":"https://pypi.org/project/kafka-helmsman/99.0.4/"},{"url":"https://pypi.org/project/kafka-helmsman/99.0.5/"},{"url":"https://pypi.org/project/kafka-helmsman/99.0.6/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-10-09T07:36:09.688Z","slug":"MAL-2026-17702","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (75536e8621da28a0e941bd4a607da879a64ab71214e908992bf14840ed9a20b2)\nThe sdist for kafka-helmsman 99.0.5 is a dependency-confusion placeholder targeting the internal Tesla project name github.com/teslamotors/kafka-helmsman. setup.py contains no build logic; its top-level code starts a daemon thread that collects hostname, current working directory, os.uname output, a timestamp, and a UUID, then POSTs the JSON body to https://webhook.site/bf5cb178-e0cf-43b6-8b1e-fb5d2f6ea9c9 and additionally transmits the same payload to the OAST host jw1yrpkm5xpav.httpcollaborator.com both over HTTPS and via DNS lookups (nslookup/getent/dig) with a base64-url path. Because setup.py executes during pip metadata and wheel build, the beacon fires on any default `pip install kafka-helmsman` and on any resolver that evaluates the sdist. The package declares packages=[] and py_modules=[] and ships no functional kafka tooling, so an installer that mis-resolved the public name instead of the internal one receives only the exfiltration payload. README framing of the artifact as Bugcrowd/Tesla research does not change the behavior: installer-identifying data is sent to hardcoded third-party endpoints controlled by the author.\n\n## Source: kam193 (edc880a17d2b3a9eaeadd0a074e6debc3f507d7afbd4ac8f5c4928209fadbcde)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n## Source: ossf-package-analysis (a2d266a2b4e9df8f2466cfb34e58fe98c636cb75d4ad1ec08cee919bd9a86588)\nThe OpenSSF Package Analysis project identified 'kafka-helmsman' @ 99.0.1 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n\n## Affected packages\n\n- `kafka-helmsman`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}