Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

gcphelpitPyPI

gcphelpit is a confirmed malicious PyPI package (MAL-2026-15810) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.0, 0.1.1, 0.1.2). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in gcphelpit (PyPI)

MAL-2026-15810
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall gcphelpit

What this malware does

The module src/gcphelpit/_verify.py runs at import time: it reads the installer's ~/.zshrc and POSTs the raw file contents to the hardcoded endpoint https://webhook.site/bc67d797-61ff-4f3b-a9b8-5df6a5e7643d. cli.py imports verify at the top of the module and is wired as the declared gcphelpit console_script entry point, so the read-and-upload fires unconditionally on every CLI invocation. ~/.zshrc routinely contains exported cloud credentials and access tokens (AWS*, GOOGLE_APPLICATION_CREDENTIALS, GitHub/npm tokens), so the effect is bulk exfiltration of installer-owned shell secrets to a third-party public webhook collector that is unrelated to the package's advertised purpose as a GCP CLI audit helper.

During initialization of the CLI, the package exfiltrates sensitive files. Prior version 0.1.2 the code was launching a calculator as PoC instead of exfiltrating data.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-gcphelpit

Reasons (based on the campaign):

  • files-exfiltration

Malicious versions

3 flagged
0.1.00.1.10.1.2

Indicators of compromise (SHA-256)

d3e108475330381be537963456cb012b943f2d0a3693c83205f8f5b01f36635a
38e7bf3f1271f4094aa294a361c60b2bc393405a95b6f5f92eb86452c76c7ddf
6be1770a21667861e10f778ca485b270170e20a35a529bc2a041bc72266bdb7d

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for gcphelpit (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging gcphelpit across your stack and pipelines.

  2. If you installed it — respond

    gcphelpit is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If gcphelpit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks gcphelpit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. gcphelpit on PyPI has been identified as a malicious package (versions 0.1.0, 0.1.1, 0.1.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-09-gcphelpitIN-MAL-2026-019320

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks gcphelpit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

gcphelpit (PyPI) malicious package — MAL-2026-15810 | O3 Security