---
id: MAL-2026-10992
title: Malicious code in dev-helper-bg (PyPI)
summary: Malicious code in dev-helper-bg (PyPI)
severity: none
vendor: dev-helper-bg
product: dev-helper-bg
ecosystem: pip
affected:
  - dev-helper-bg
published: '2026-07-22'
updated: '2026-07-23'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10992'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/dev-helper-bg'
tags:
  - osv
  - pip
ingestedAt: '2026-07-23T19:05:52.761Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (9466ff28252daa546dc9a75b6b255e94dc6a6409d69197b40b573d05d002d340)
The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-make-helper


Reasons (based on the campaign):


 - files-exfiltration


 - obfuscation


 - uses-telegram-bot


## Affected packages

- `dev-helper-bg`

## Remediation

Refer to the advisory for the patched release.
