logo

Xinference PyPI Package Compromised With Malicious Code to Steal Cloud Credentials

ID: bbb2bca3-8208-5ce8-8ee7-d0147ff956c4

STIX ID: report--bbb2bca3-8208-5ce8-8ee7-d0147ff956c4

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: AnuPriya

...
...

A supply-chain attack infected Xinference PyPI package versions 2.6.0–2.6.2 with an obfuscated infostealer that executes on import and harvests AWS/GCP credentials, Kubernetes tokens, SSH keys, API keys, database credentials, wallet data and other secrets, exfiltrating them to whereisitat.lucyatemysuperbox.space; maintainers identified 2.5.0 as the last safe release and recommend downgrading, rotating credentials, enabling MFA, and auditing logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.