{"id":"MAL-2026-17702","summary":"Malicious code in kafka-helmsman (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (75536e8621da28a0e941bd4a607da879a64ab71214e908992bf14840ed9a20b2)\nThe sdist for kafka-helmsman 99.0.5 is a dependency-confusion placeholder targeting the internal Tesla project name github.com/teslamotors/kafka-helmsman. setup.py contains no build logic; its top-level code starts a daemon thread that collects hostname, current working directory, os.uname output, a timestamp, and a UUID, then POSTs the JSON body to https://webhook.site/bf5cb178-e0cf-43b6-8b1e-fb5d2f6ea9c9 and additionally transmits the same payload to the OAST host jw1yrpkm5xpav.httpcollaborator.com both over HTTPS and via DNS lookups (nslookup/getent/dig) with a base64-url path. Because setup.py executes during pip metadata and wheel build, the beacon fires on any default `pip install kafka-helmsman` and on any resolver that evaluates the sdist. The package declares packages=[] and py_modules=[] and ships no functional kafka tooling, so an installer that mis-resolved the public name instead of the internal one receives only the exfiltration payload. README framing of the artifact as Bugcrowd/Tesla research does not change the behavior: installer-identifying data is sent to hardcoded third-party endpoints controlled by the author.\n\n## Source: kam193 (edc880a17d2b3a9eaeadd0a074e6debc3f507d7afbd4ac8f5c4928209fadbcde)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n## Source: ossf-package-analysis (a2d266a2b4e9df8f2466cfb34e58fe98c636cb75d4ad1ec08cee919bd9a86588)\nThe OpenSSF Package Analysis project identified 'kafka-helmsman' @ 99.0.1 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-10-09T01:00:08.497849713Z","published":"2026-10-08T21:15:56Z","database_specific":{"malicious-packages-origins":[{"sha256":"a2d266a2b4e9df8f2466cfb34e58fe98c636cb75d4ad1ec08cee919bd9a86588","source":"ossf-package-analysis","versions":["99.0.1"],"import_time":"2026-10-08T21:18:09.362483578Z","modified_time":"2026-10-08T21:15:56Z"},{"sha256":"0431384cc0de119177c0a345db1bfa2277fa4707e726176e542c0babfe1cd1f2","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-021263","import_time":"2026-10-08T21:42:57.408970022Z","modified_time":"2026-10-08T21:23:11Z"},{"source":"amazon-inspector","versions":["99.0.2"],"id":"IN-MAL-2026-021239","import_time":"2026-10-08T21:42:55.500895338Z","modified_time":"2026-10-08T21:19:45Z","sha256":"a99759eb9821bcb30598eea10347dd1523ce42ec1847b9b66c5ba857ccd24785"},{"source":"amazon-inspector","versions":["99.0.3"],"id":"IN-MAL-2026-021261","import_time":"2026-10-08T21:42:57.246496983Z","modified_time":"2026-10-08T21:22:52Z","sha256":"d2d1d7c99040594bd5c9bb0f23a58703e1fa5f1cd15cafbe2abb3e04aa3667be"},{"versions":["99.0.1","99.0.2","99.0.3","99.0.4","99.0.5","99.0.6"],"id":"pypi/GENERIC-standard-pypi-install-pentest/kafka-helmsman","import_time":"2026-10-08T22:18:58.155762443Z","modified_time":"2026-10-08T21:36:02.265925Z","sha256":"edc880a17d2b3a9eaeadd0a074e6debc3f507d7afbd4ac8f5c4928209fadbcde","source":"kam193"},{"source":"amazon-inspector","versions":["99.0.4"],"id":"IN-MAL-2026-021277","import_time":"2026-10-09T00:53:54.88986955Z","modified_time":"2026-10-09T00:05:25Z","sha256":"10f61c10a25e4aa02e6d142d652627c1e4f3033158e22d77e4bb5e96cf0562dd"},{"import_time":"2026-10-09T00:53:54.955403434Z","modified_time":"2026-10-09T00:05:33Z","sha256":"75536e8621da28a0e941bd4a607da879a64ab71214e908992bf14840ed9a20b2","source":"amazon-inspector","versions":["99.0.5"],"id":"IN-MAL-2026-021278"},{"source":"amazon-inspector","versions":["99.0.6"],"id":"IN-MAL-2026-021275","import_time":"2026-10-09T00:53:54.75052438Z","modified_time":"2026-10-09T00:05:06Z","sha256":"c52e0a7a9f07e1f3f9f17afa3bc2328c1743da9f3d81c421164c92282bc5fe92"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/kafka-helmsman/99.0.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/kafka-helmsman/99.0.2/"},{"type":"PACKAGE","url":"https://pypi.org/project/kafka-helmsman/99.0.3/"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/kafka-helmsman"},{"type":"PACKAGE","url":"https://pypi.org/project/kafka-helmsman/99.0.4/"},{"type":"PACKAGE","url":"https://pypi.org/project/kafka-helmsman/99.0.5/"},{"type":"PACKAGE","url":"https://pypi.org/project/kafka-helmsman/99.0.6/"}],"affected":[{"package":{"name":"kafka-helmsman","ecosystem":"PyPI","purl":"pkg:pypi/kafka-helmsman"},"versions":["99.0.1","99.0.2","99.0.3","99.0.4","99.0.5","99.0.6"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/kafka-helmsman/MAL-2026-17702.json","indicators":{"evidence_files":[{"sha256":"d4f2a3ca94be78472bbb15bad6e215cd59d0b00ecebbf4e0fc4b70b837f72e56","tlsh":"2f61a783c4142c63d2c360944475e9613722790b7d036cfa7aec9395af4f47680f256e","path":"setup.py"}],"package_integrity":[{"hashes":{"blake2b_256":"189004a13858578492254d2b8e01d434f597c5a1ed1ad619f65ac2bd082fc82b","md5":"95fd10a2179b8c31d0de2cbd8913de78","sha256":"8fb9ae3af1e1bba7231812809b21be6c7a9a1b07a08ee2b668c6e323ec7a2500"},"filename":"kafka_helmsman-99.0.1.tar.gz"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}