logo

“SymPy” Imposter: Typosquatting Attack Turns Math Library into Crypto Miner

ID: 9f823fb2-1b65-592d-a30a-7e03f9ad5f48

STIX ID: report--9f823fb2-1b65-592d-a30a-7e03f9ad5f48

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: Ddos

...
...

A malicious typosquatted PyPI package named "sympy-dev" impersonated the popular SymPy library to deliver a staged downloader that fetches and executes an ELF payload (observed as XMRig) in-memory using memfd_create, evading disk-based detection; the package saw over 1,000 downloads on its first day (published 2026-01-17) and researchers warn the chain enables arbitrary code execution and reuse for other payloads, recommending dependency pinning and integrity checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.