VDB
KO

MAL-2026-11516

Malicious code in coldcard-helpers (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3) When installing the package or importing the module, code starts a background task collecting sensitive data, like sensitive environment variables, private keys for cryptocurrency wallets, SSH keys, and so on to a Telegram channel.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-coldcard-helpers

Reasons (based on the campaign):

- exfiltration-env-variables

- exfiltration-ssh-keys

- exfiltration-crypto

- exfiltration-credentials

- uses-telegram-bot

- The package overrides the install command in setup.py to execute malicious code during installation.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / coldcard-helpers

No fixed version published yet for coldcard-helpers (pip). Pin to a known-safe version or switch to an alternative.

References