logo

A Poisoned Xinference Package Targets AI Inference Servers

ID: c0e7328c-36df-53af-969e-21a2c6c04398

STIX ID: report--c0e7328c-36df-53af-969e-21a2c6c04398

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Tom Abai

...
...

Mend reported three malicious xinference PyPI releases (2.6.0–2.6.2) that execute on import to collect exhaustive credentials (SSH keys, cloud IAM tokens, Kubernetes tokens, Docker and DB credentials, and multiple cryptocurrency wallet formats) and POST them to a C2 endpoint (https://whereisitat.lucyatemysuperbox.space/) with a custom header. The implant uses double-base64 payloads, creates a transient gzipped staging archive (love.tar.gz), leaves no persistence artifacts, and therefore requires rotation of any exposed credentials; the campaign mirrors prior TeamPCP waves though attribution is disputed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.