MAL-2026-17703Critical▾ Abyssal⚠ Exploited in the wildMalicious code in kafka-roller (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
-= Per source details. Do not edit below this line.=-
The package is published to PyPI under the name kafka-roller with metadata impersonating Tesla's teslamotors/kafka-helmsman project (homepage points at github.com/teslamotors/kafka-helmsman while the publisher is an unaffiliated account), and version 99.0.4 is pinned implausibly high — the dependency-confusion squat shape. setup.py starts a module-level daemon thread during pip's metadata/wheel build that collects hostname, current working directory, platform information, a timestamp and a UUID, and transmits them via HTTPS POST to https://webhook.site/bf5cb178-e0cf-43b6-8b1e-fb5d2f6ea9c9 and via HTTPS GET plus DNS lookups to a subdomain of oast.site (an interactsh out-of-band collector). The DNS channel is driven by subprocess invocations of nslookup/getent/dig against an attacker-chosen hostname, providing a secondary exfiltration path that bypasses HTTP egress filtering. The beacon fires on any pip processing of the sdist without installer consent, and leaks internal host and build-environment identifiers for any build system that misresolves the kafka-roller name to this PyPI package. A self-description as 'dependency-confusion security research' does not change the behavior: install-time out-of-band callbacks carrying host identifiers to attacker-controlled collectors are exfiltration regardless of framing.
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
The OpenSSF Package Analysis project identified 'kafka-roller' @ 99.0.0 (pypi) as malicious.
It is considered malicious because:
kafka-rollerRefer to the advisory for the patched release.