Malicious code in logghelper (PyPI)
Malware
Published
Jul 21, 2026
to the GitHub Advisory Database
•
Updated Jul 21, 2026
Description
Published to the GitHub Advisory Database
Jul 21, 2026
Reviewed
Jul 21, 2026
Last updated
Jul 21, 2026
Source: kam193 (2a5f0848002e1727d885bdf20c39e4949fd9609a4df5164a8c42ccc870aa6736)
Code attempts to download and run malware, as well as keeps ability to execute files sent via Telegram C2 channel
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-07-logghelper
Reasons (based on the campaign):
malware
infostealer
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Credit: OpenSSF (source)
References