MAL-2026-11516
Malicious code in coldcard-helpers (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3) When installing the package or importing the module, code starts a background task collecting sensitive data, like sensitive environment variables, private keys for cryptocurrency wallets, SSH keys, and so on to a Telegram channel.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-coldcard-helpers
Reasons (based on the campaign):
- exfiltration-env-variables
- exfiltration-ssh-keys
- exfiltration-crypto
- exfiltration-credentials
- uses-telegram-bot
- The package overrides the install command in setup.py to execute malicious code during installation.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for coldcard-helpers (pip). Pin to a known-safe version or switch to an alternative.