CRITICAL PyPI Malware

Malicious code in xinference (PyPI)

MAL-2026-3000

Published · Modified

Dependency scanning

Check whether xinference is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: kam193 (1d006f6a08c959393160456d4ace221fd165b6d609fc8356ebfb041979aef93d)

Versions 2.6.0, 2.6.1, 2.6.2 were compromised.

Following a malicious pull request that exfiltrated sensitive data from the CI runner, three malicious PyPI releases were published. Infected releases contain code typical for TeamPCP actions that exfiltrates all kinds of sensitive data (credentials, env variables, SSH keys, cloud tokens, configuration files, shell histories, cryptowallets, data from secret managers...). Malicious action activates during importing the main package's module. TeamPCP denies their involvement.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-teampcp

Reasons (based on the campaign):

  • exfiltration-env-variables

  • exfiltration-ssh-keys

  • obfuscation

  • exfiltration-cloud-tokens

  • exfiltration-crypto

  • exfiltration-credentials

  • compromised-package

  • exploited-ci-vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes