---
id: MAL-2026-17702
title: Malicious code in kafka-helmsman (PyPI)
summary: Malicious code in kafka-helmsman (PyPI)
severity: critical
exploited: true
vendor: kafka-helmsman
product: kafka-helmsman
ecosystem: pip
affected:
  - kafka-helmsman
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T01:00:08.497849713Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17702'
references:
  - url: 'https://pypi.org/project/kafka-helmsman/99.0.1/'
  - url: 'https://pypi.org/project/kafka-helmsman/99.0.2/'
  - url: 'https://pypi.org/project/kafka-helmsman/99.0.3/'
  - url: 'https://bad-packages.kam193.eu/pypi/package/kafka-helmsman'
  - url: 'https://pypi.org/project/kafka-helmsman/99.0.4/'
  - url: 'https://pypi.org/project/kafka-helmsman/99.0.5/'
  - url: 'https://pypi.org/project/kafka-helmsman/99.0.6/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-10-09T07:36:09.688Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (75536e8621da28a0e941bd4a607da879a64ab71214e908992bf14840ed9a20b2)
The sdist for kafka-helmsman 99.0.5 is a dependency-confusion placeholder targeting the internal Tesla project name github.com/teslamotors/kafka-helmsman. setup.py contains no build logic; its top-level code starts a daemon thread that collects hostname, current working directory, os.uname output, a timestamp, and a UUID, then POSTs the JSON body to https://webhook.site/bf5cb178-e0cf-43b6-8b1e-fb5d2f6ea9c9 and additionally transmits the same payload to the OAST host jw1yrpkm5xpav.httpcollaborator.com both over HTTPS and via DNS lookups (nslookup/getent/dig) with a base64-url path. Because setup.py executes during pip metadata and wheel build, the beacon fires on any default `pip install kafka-helmsman` and on any resolver that evaluates the sdist. The package declares packages=[] and py_modules=[] and ships no functional kafka tooling, so an installer that mis-resolved the public name instead of the internal one receives only the exfiltration payload. README framing of the artifact as Bugcrowd/Tesla research does not change the behavior: installer-identifying data is sent to hardcoded third-party endpoints controlled by the author.

## Source: kam193 (edc880a17d2b3a9eaeadd0a074e6debc3f507d7afbd4ac8f5c4928209fadbcde)
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


---

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.


Campaign: GENERIC-standard-pypi-install-pentest


Reasons (based on the campaign):


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.


 - The package overrides the install command in setup.py to execute malicious code during installation.

## Source: ossf-package-analysis (a2d266a2b4e9df8f2466cfb34e58fe98c636cb75d4ad1ec08cee919bd9a86588)
The OpenSSF Package Analysis project identified 'kafka-helmsman' @ 99.0.1 (pypi) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.


## Affected packages

- `kafka-helmsman`

## Remediation

Refer to the advisory for the patched release.
