A Poisoned Xinference Package Targets AI Inference Servers
ID: c0e7328c-36df-53af-969e-21a2c6c04398
STIX ID: report--c0e7328c-36df-53af-969e-21a2c6c04398
Feed Name: Security Boulevard
Mend reported three malicious xinference PyPI releases (2.6.0–2.6.2) that execute on import to collect exhaustive credentials (SSH keys, cloud IAM tokens, Kubernetes tokens, Docker and DB credentials, and multiple cryptocurrency wallet formats) and POST them to a C2 endpoint (https://whereisitat.lucyatemysuperbox.space/) with a custom header. The implant uses double-base64 payloads, creates a transient gzipped staging archive (love.tar.gz), leaves no persistence artifacts, and therefore requires rotation of any exposed credentials; the campaign mirrors prior TeamPCP waves though attribution is disputed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
