VDB
KO

MAL-2026-13666

Malicious code in cubesat-upstream-driver (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (d669fdf7584f17d952cec3ed432bdb8f07672b43c3bc42ae68aa2d042d51481b) Package appears to abuse PyPI for a CTF-like exercise. It can collect up to all environment variables. The package does not exfiltrate them on its own, suggesting there is another external trigger for that.

Originally detected by Aikido.

---

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2026-08-cubesat-upstream-driver

Reasons (based on the campaign):

- dependency-confusion

- other

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / cubesat-upstream-driver

No fixed version published yet for cubesat-upstream-driver (pip). Pin to a known-safe version or switch to an alternative.

References