Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·osv

Malicious code in mlflow-ui (PyPI)

mlflow-ui

Risk score

92

AI summary

Indexed incident for mlflow-ui (pypi).

Description

During installation, the package first collects local information, environment variables, and probes connections to typically expected services like databanks. Results are exfiltrated and then, the next stage code is downloaded and executed. It then continues exfiltrating data by looking for credentials to databases, exfiltrating SQLite databases and bruteforcing&exfiltrating other databases reachable from the running environment.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-mlflow-ui

Reasons (based on the campaign):

  • files-exfiltration

  • exfiltration-env-variables

  • dependency-confusion

  • Downloads and executes a remote malicious script.

  • exfiltration-credentials

  • network-scan

  • exfiltration-cloud-tokens

Technical details

Affected versions

=2.7.1=2.7.2=2.7.3

Indicators

  • affected version=2.7.175%
  • affected version=2.7.275%
  • affected version=2.7.375%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents