logo

AI Malware Dressed Up as DeepSeek Packages Lurk in PyPi

ID: e288e755-55f7-56ef-98a2-f7aaca762139

STIX ID: report--e288e755-55f7-56ef-98a2-f7aaca762139

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2025-02-03

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Researchers discovered PyPI typosquatting packages named 'deepseekai' and 'deepseeek' that impersonated the DeepSeek project and dropped infostealer malware to steal API keys, database credentials, and environment secrets; the 'bvk' account published the packages (active Jan 29), they were downloaded dozens to hundreds of times before removal, and analysis indicates the malicious code was likely written with AI assistance — developers are advised to verify package sources, use SCA and dependency scanning, and limit unverified packages in development environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.