MAL-2026-11521

    Dashboard / Malicious Package / MAL-2026-11521

    MAL-2026-11521

    Published: 4 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in psbt-helpers (PyPI)

    Details: Source: kam193 (82a309d768af6a39f95bb4f7c9f5d8548a95f0074613985f49f0513420dae9fa) The code advertised as a firmware upgrader for hardware wallets in fact downloads an infostealer. The stealer searches the machine for cryptocurrency sensitive data (wallet files, seeds), browser data (passwords, cookies), all kinds of credentials (including tokens, passwords, SSH keys, TOTP seeds etc.), other sensitive files and current clipboard content. Data are exfiltrated, and the stealer configures persistence via scheduled tasks or LaunchAgent. The code deliberatly doesn't start in CI environments and checks if the system looks real. Continuation of 2026-08-coldcard-helpers campaign. Related packages are used in malicious repository https://github.com/domaup/coldcard-poc Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-psbt-utils Reasons (based on the campaign): - infostealer - files-exfiltration - clipboard-stealing - exfiltration-ssh-keys - obfuscation - crypto-related - exfiltration-cloud-tokens - Downloads and executes a remote malicious script. - exfiltration-browser-data - exfiltration-crypto - exfiltration-credentials - persistence

    Affected packages

    Package

    Name: psbt-helpers

    Purl: pkg:pypi/psbt-helpers

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0