logo

DeepSeek AI tools impersonated by infostealer malware on PyPI

ID: 481307d3-1510-53b7-af15-7a0538f42899

STIX ID: report--481307d3-1510-53b7-af15-7a0538f42899

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-02-03

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Positive Technologies discovered two malicious PyPI packages (deepseeek and deepseekai) impersonating DeepSeek AI that, when executed, stole developer user/system data and environment variables (API keys, tokens, DB credentials) and exfiltrated them to a Pipedream C2; the packages were removed after being downloaded 222 times and affected developers should rotate credentials and review cloud resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.