Malicious code in coldcard-helpers (PyPI)
The PyPI package coldcard-helpers was compromised with malicious code that exfiltrates sensitive data including environment variables, cryptocurrency private keys, and SSH keys to a Telegram channel. The malicious payload executes during package installation via a setup.py override.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation prevalence of the malicious package version(s).
- Ecosystems
- Attack vectors
- Affected entities
- coldcard-helpersPyPI package containing malicious code
The coldcard-helpers package on PyPI was found to contain malicious code designed to steal sensitive information from affected systems. When the package is installed or imported, it initiates a background task that collects and exfiltrates sensitive data including environment variables, private keys for cryptocurrency wallets, SSH keys, and other credentials to a Telegram channel.\n\nThe attack vector leverages a setup.py override to execute the malicious code during the installation process, ensuring execution before the legitimate package functionality is available. This technique allows the attacker to compromise systems at installation time.\n\nThe malicious campaign (2026-08-coldcard-helpers) was identified and credited to the OpenSSF's malicious-packages repository. The package has been flagged with the hash 127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3.
Indicators of compromise
- Packages
- coldcard-helpers
- Hashes
- 127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3
Remediation
- Immediately uninstall coldcard-helpers from all affected systems
- Audit environment variables and secrets that may have been exposed
- Rotate all cryptocurrency wallet private keys and SSH keys that may have been compromised
- Review Telegram bot activity and account access logs for unauthorized access
- Check system logs for suspicious background processes or network connections during the installation period
- Use pip to search for and remove any cached or installed versions of the malicious package
- Consider using dependency scanning tools to detect similar malicious packages in your supply chain
Sources
- GitHub Advisory GHSA-8vw6-pp4v-8j32 · GitHub Advisory Database
Cite this entry
"Malicious code in coldcard-helpers (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/malicious-code-in-coldcard-helpers-pypi-1hbx0l
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in instalogin1234 (PyPI)
The instalogin1234 package on PyPI contained malicious code that harvested user credentials. When users attempted to log in via the fake Instagram CLI, their credentials were exfiltrated to a Discord channel before displaying the legitimate Instagram website.
PyPICompromised package - resolvedcritical
Malicious code in wacve-utils (PyPI)
The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.
PyPICompromised package - containedcritical
Malicious code in trongriden (PyPI)
Malicious package trongriden published to PyPI designed for private key exfiltration, part of a broader 2025-04-tronix campaign targeting cryptocurrency users. No known usage has been reported.
2025 04 TronixPyPICompromised package - resolvedhigh
Malicious code in asdk-plugin-ai-platform (PyPI)
The PyPI package asdk-plugin-ai-platform contained malicious code that exfiltrates basic host information (IP, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package