“SymPy” Imposter: Typosquatting Attack Turns Math Library into Crypto Miner
ID: 9f823fb2-1b65-592d-a30a-7e03f9ad5f48
STIX ID: report--9f823fb2-1b65-592d-a30a-7e03f9ad5f48
Feed Name: securityonline.info
Threat Score
A malicious typosquatted PyPI package named "sympy-dev" impersonated the popular SymPy library to deliver a staged downloader that fetches and executes an ELF payload (observed as XMRig) in-memory using memfd_create, evading disk-based detection; the package saw over 1,000 downloads on its first day (published 2026-01-17) and researchers warn the chain enables arbitrary code execution and reuse for other payloads, recommending dependency pinning and integrity checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
