THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalpypi·maintainer compromise·osv

Malicious code in xinference (PyPI)

xinference

Risk score

92

AI summary

Indexed incident for xinference (pypi).

Description

Versions 2.6.0, 2.6.1, 2.6.2 were compromised.

Following a malicious pull request that exfiltrated sensitive data from the CI runner, three malicious PyPI releases were published. Infected releases contain code typical for TeamPCP actions that exfiltrates all kinds of sensitive data (credentials, env variables, SSH keys, cloud tokens, configuration files, shell histories, cryptowallets, data from secret managers...). Malicious action activates during importing the main package's module. TeamPCP denies their involvement.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-teampcp

Reasons (based on the campaign):

  • exfiltration-env-variables

  • exfiltration-ssh-keys

  • obfuscation

  • exfiltration-cloud-tokens

  • exfiltration-crypto

  • exfiltration-credentials

  • compromised-package

  • exploited-ci-vulnerability

Technical details

Affected versions

=2.6.0=2.6.1=2.6.2

Indicators

  • affected version=2.6.075%
  • affected version=2.6.175%
  • affected version=2.6.275%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents