logo

Xinference PyPI Breach Exposes Developers to Cloud Credential Theft

ID: ac5add21-318a-508d-bd5c-882a2f70c391

STIX ID: report--ac5add21-318a-508d-bd5c-882a2f70c391

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Divya

...
...

A supply-chain attack on the Xinference PyPI package (malicious versions 2.6.0–2.6.2) implanted an obfuscated infostealer in __init__.py that executes on import and exfiltrates developer secrets — including cloud configs, SSH keys, API keys, database credentials, and cryptocurrency wallets. The compromise reportedly began after a likely-compromised automated account (XprobeBot) committed a base64 payload; users are advised to downgrade to 2.5.0, rotate credentials, enable 2FA, audit environments and pin dependencies immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.