Malicious code in cubesat-upstream-driver (PyPI)
Malware
Published
Aug 9, 2026
to the GitHub Advisory Database
•
Updated Aug 10, 2026
Description
Published to the GitHub Advisory Database
Aug 9, 2026
Reviewed
Aug 9, 2026
Last updated
Aug 10, 2026
Source: kam193 (d669fdf7584f17d952cec3ed432bdb8f07672b43c3bc42ae68aa2d042d51481b)
Package appears to abuse PyPI for a CTF-like exercise. It can collect up to all environment variables. The package does not exfiltrate them on its own, suggesting there is another external trigger for that.
Originally detected by Aikido.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2026-08-cubesat-upstream-driver
Reasons (based on the campaign):
dependency-confusion
other
Credit: OpenSSF (source)
References