---
id: MAL-2026-10991
title: Malicious code in make-helper (PyPI)
summary: Malicious code in make-helper (PyPI)
severity: none
vendor: make-helper
product: make-helper
ecosystem: pip
affected:
  - make-helper
published: '2026-07-22'
updated: '2026-07-23'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10991'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/make-helper'
tags:
  - osv
  - pip
ingestedAt: '2026-07-23T19:05:52.739Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (39bf40d5056dc821bcedf5fcc304e26d9e6566f5beb508b6a01874b49d32becd)
The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-make-helper


Reasons (based on the campaign):


 - files-exfiltration


 - obfuscation


 - uses-telegram-bot


## Affected packages

- `make-helper`

## Remediation

Refer to the advisory for the patched release.
