logo

3 New Malicious PyPI Packages Found Installing CoinMiner on Linux Devices

ID: 7646afd3-a37c-5a6c-93d0-4f2e5dcd9ddc

STIX ID: report--7646afd3-a37c-5a6c-93d0-4f2e5dcd9ddc

Feed Name: GBHackers

Threat Score
68/100

Date Published: 2024-01-05

Date Updated: 2026-04-22

Author: Guru baran

...
...

Researchers found multiple malicious PyPI packages published by a new author that perform a multi-stage attack to deploy a CoinMiner on Linux hosts: the packages import a processor module that fetches a remote unmi.sh script, which downloads a mining configuration and an ELF miner, runs it with nohup, and ensures persistence by appending startup commands to ~/.bashrc. The campaign reuses and improves techniques from an earlier 'culturestreak' miner, employing obfuscation, random filenames, and remote-hosted payloads to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.