Xinference PyPI Package Compromised With Malicious Code to Steal Cloud Credentials
ID: bbb2bca3-8208-5ce8-8ee7-d0147ff956c4
STIX ID: report--bbb2bca3-8208-5ce8-8ee7-d0147ff956c4
Feed Name: Cyber Press
Threat Score
A supply-chain attack infected Xinference PyPI package versions 2.6.0–2.6.2 with an obfuscated infostealer that executes on import and harvests AWS/GCP credentials, Kubernetes tokens, SSH keys, API keys, database credentials, wallet data and other secrets, exfiltrating them to whereisitat.lucyatemysuperbox.space; maintainers identified 2.5.0 as the last safe release and recommend downgrading, rotating credentials, enabling MFA, and auditing logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
