← Back to Pulse Feed
PULSE DETAIL
On April 22, 2026, NSFOCUS CERT reported a supply chain poisoning incident involving the Xinference library on the Python Package Index (PyPI). Attackers compromised the release permission credentials of Xinference maintainers, leading to the release of three malicious library versions. These versions contained Trojans that, upon user execution, would exfiltrate sensitive data like cloud credentials, SSH keys, API tokens, database passwords, and environment variable configurations to the attackers' command and control (C2) server.
Indicators of Compromise (10)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 3ee893ae46530b92e0d26435fb979d82 | — | 2026-04-26 | |
| FileHash-MD5 | 484067fd6232f7cdd7b664b33857fc2c | — | 2026-04-26 | |
| FileHash-MD5 | 971670c10eff28339a085ca50a600e35 | — | 2026-04-26 | |
| FileHash-MD5 | 9b3257e45b27a6bbe4e240e41a3a306f | — | 2026-04-26 | |
| FileHash-MD5 | c6ce4e25f7fe3e3bb1eea2e9052483bf | — | 2026-04-26 | |
| FileHash-MD5 | e291734d46c313a23d676681499f8846 | — | 2026-04-26 | |
| FileHash-SHA256 | 077d49fa708f498969d7cdffe701eb64675baaa4968ded9bd97a4936dd56c21c | — | 2026-04-26 | |
| FileHash-SHA256 | e1e007ce4eab7774785617179d1c01a9381ae83abfd431aae8dba6f82d3ac127 | — | 2026-04-26 | |
| URL | https://whereisitat.lucyatemysuperbox.space | — | 2026-04-26 | |
| hostname | whereisitat.lucyatemysuperbox.space | — | 2026-04-26 |