logo

Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference

ID: 8392eaae-d591-51de-ba89-50efd2249306

STIX ID: report--8392eaae-d591-51de-ba89-50efd2249306

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

The report describes a supply-chain compromise of the Xinference PyPI package (versions 2.6.0–2.6.2) where TeamPCP implanted a two-stage, in-memory credential-stealing payload that collects cloud IAM/metadata, secrets (AWS/GCP/Azure), developer tokens, SSH/Docker/Kubernetes artifacts, TLS private keys, CI/CD files, and crypto wallets, bundles them as love.tar.gz, and exfiltrates to whereisitat.lucyatemysuperbox.space; malicious releases were removed from PyPI but any installations from April 22 should immediately verify package version, downgrade to <2.6.0, and rotate all exposed credentials and keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.