---
id: MAL-2026-13666
title: Malicious code in cubesat-upstream-driver (PyPI)
summary: Malicious code in cubesat-upstream-driver (PyPI)
severity: none
vendor: cubesat-upstream-driver
product: cubesat-upstream-driver
ecosystem: pip
affected:
  - cubesat-upstream-driver
published: '2026-08-09'
updated: '2026-08-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-13666'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/cubesat-upstream-driver'
tags:
  - osv
  - pip
ingestedAt: '2026-08-09T19:16:05.720Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (d669fdf7584f17d952cec3ed432bdb8f07672b43c3bc42ae68aa2d042d51481b)
Package appears to abuse PyPI for a CTF-like exercise. It can collect up to all environment variables. The package does not exfiltrate them on its own, suggesting there is another external trigger for that.

Originally detected by Aikido.


---

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.


Campaign: 2026-08-cubesat-upstream-driver


Reasons (based on the campaign):


 - dependency-confusion


 - other


## Affected packages

- `cubesat-upstream-driver`

## Remediation

Refer to the advisory for the patched release.
