Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in coldcard-helpers (PyPI)

The PyPI package coldcard-helpers was compromised with malicious code that exfiltrates sensitive data including environment variables, cryptocurrency private keys, and SSH keys to a Telegram channel. The malicious payload executes during package installation via a setup.py override.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation prevalence of the malicious package version(s).
Ecosystems
Attack vectors
Affected entities
  • coldcard-helpersPyPI package containing malicious code

The coldcard-helpers package on PyPI was found to contain malicious code designed to steal sensitive information from affected systems. When the package is installed or imported, it initiates a background task that collects and exfiltrates sensitive data including environment variables, private keys for cryptocurrency wallets, SSH keys, and other credentials to a Telegram channel.\n\nThe attack vector leverages a setup.py override to execute the malicious code during the installation process, ensuring execution before the legitimate package functionality is available. This technique allows the attacker to compromise systems at installation time.\n\nThe malicious campaign (2026-08-coldcard-helpers) was identified and credited to the OpenSSF's malicious-packages repository. The package has been flagged with the hash 127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3.

Indicators of compromise

Packages
  • coldcard-helpers
Hashes
  • 127a096109f7b5b2bbedf7f6a9fc2e7baa706e93704ebd52615e744a9838fbc3

Remediation

  • Immediately uninstall coldcard-helpers from all affected systems
  • Audit environment variables and secrets that may have been exposed
  • Rotate all cryptocurrency wallet private keys and SSH keys that may have been compromised
  • Review Telegram bot activity and account access logs for unauthorized access
  • Check system logs for suspicious background processes or network connections during the installation period
  • Use pip to search for and remove any cached or installed versions of the malicious package
  • Consider using dependency scanning tools to detect similar malicious packages in your supply chain

Sources

  1. GitHub Advisory GHSA-8vw6-pp4v-8j32 · GitHub Advisory Database

Cite this entry

"Malicious code in coldcard-helpers (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/malicious-code-in-coldcard-helpers-pypi-1hbx0l

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in instalogin1234 (PyPI)

    The instalogin1234 package on PyPI contained malicious code that harvested user credentials. When users attempted to log in via the fake Instagram CLI, their credentials were exfiltrated to a Discord channel before displaying the legitimate Instagram website.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in wacve-utils (PyPI)

    The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.

    PyPICompromised package
  3. containedcritical

    Malicious code in trongriden (PyPI)

    Malicious package trongriden published to PyPI designed for private key exfiltration, part of a broader 2025-04-tronix campaign targeting cryptocurrency users. No known usage has been reported.

    2025 04 TronixPyPICompromised package
  4. resolvedhigh

    Malicious code in asdk-plugin-ai-platform (PyPI)

    The PyPI package asdk-plugin-ai-platform contained malicious code that exfiltrates basic host information (IP, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.

    PyPICompromised package