Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
ID: 8392eaae-d591-51de-ba89-50efd2249306
STIX ID: report--8392eaae-d591-51de-ba89-50efd2249306
Feed Name: securityonline.info
The report describes a supply-chain compromise of the Xinference PyPI package (versions 2.6.0–2.6.2) where TeamPCP implanted a two-stage, in-memory credential-stealing payload that collects cloud IAM/metadata, secrets (AWS/GCP/Azure), developer tokens, SSH/Docker/Kubernetes artifacts, TLS private keys, CI/CD files, and crypto wallets, bundles them as love.tar.gz, and exfiltrates to whereisitat.lucyatemysuperbox.space; malicious releases were removed from PyPI but any installations from April 22 should immediately verify package version, downgrade to <2.6.0, and rotate all exposed credentials and keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
