VDB
Sign up

MAL-2026-15828

Malicious code in env-validator-tool (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff) In this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-telemetry-helper

Reasons (based on the campaign):

- exfiltration-env-variables

- The malicious code is intentionally included in a dependency of the package

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/env-validator-tool

No fixed version published yet for env-validator-tool (pip). Pin to a known-safe version or switch to an alternative.

References