VDB
Sign up

MAL-2026-15810

Malicious code in gcphelpit (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (d3e108475330381be537963456cb012b943f2d0a3693c83205f8f5b01f36635a) During initialization of the CLI, the package exfiltrates sensitive files. Prior version 0.1.2 the code was launching a calculator as PoC instead of exfiltrating data.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-gcphelpit

Reasons (based on the campaign):

- files-exfiltration

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/gcphelpit

No fixed version published yet for gcphelpit (pip). Pin to a known-safe version or switch to an alternative.

References