MAL-2026-17702Critical▾ Abyssal⚠ Exploited in the wildMalicious code in kafka-helmsman (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
-= Per source details. Do not edit below this line.=-
The sdist for kafka-helmsman 99.0.5 is a dependency-confusion placeholder targeting the internal Tesla project name github.com/teslamotors/kafka-helmsman. setup.py contains no build logic; its top-level code starts a daemon thread that collects hostname, current working directory, os.uname output, a timestamp, and a UUID, then POSTs the JSON body to https://webhook.site/bf5cb178-e0cf-43b6-8b1e-fb5d2f6ea9c9 and additionally transmits the same payload to the OAST host jw1yrpkm5xpav.httpcollaborator.com both over HTTPS and via DNS lookups (nslookup/getent/dig) with a base64-url path. Because setup.py executes during pip metadata and wheel build, the beacon fires on any default pip install kafka-helmsman and on any resolver that evaluates the sdist. The package declares packages=[] and py_modules=[] and ships no functional kafka tooling, so an installer that mis-resolved the public name instead of the internal one receives only the exfiltration payload. README framing of the artifact as Bugcrowd/Tesla research does not change the behavior: installer-identifying data is sent to hardcoded third-party endpoints controlled by the author.
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
The OpenSSF Package Analysis project identified 'kafka-helmsman' @ 99.0.1 (pypi) as malicious.
It is considered malicious because:
kafka-helmsmanRefer to the advisory for the patched release.