—
MAL-2026-15810
Malicious code in gcphelpit (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (d3e108475330381be537963456cb012b943f2d0a3693c83205f8f5b01f36635a) During initialization of the CLI, the package exfiltrates sensitive files. Prior version 0.1.2 the code was launching a calculator as PoC instead of exfiltrating data.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-gcphelpit
Reasons (based on the campaign):
- files-exfiltration
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/gcphelpit
No fixed version published yet for gcphelpit (pip). Pin to a known-safe version or switch to an alternative.