MAL-2026-15828
Malicious code in env-validator-tool (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff) In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-telemetry-helper
Reasons (based on the campaign):
- exfiltration-env-variables
- The malicious code is intentionally included in a dependency of the package
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for env-validator-tool (pip). Pin to a known-safe version or switch to an alternative.