PULSE NAME
Xinference PyPI Supply Chain Poisoning Warning
WHITE PetrP.73 2026-04-26 Modified: 2026-04-26
10
IOCs
LOW VOLUME
On April 22, 2026, NSFOCUS CERT reported a supply chain poisoning incident involving the Xinference library on the Python Package Index (PyPI). Attackers compromised the release permission credentials of Xinference maintainers, leading to the release of three malicious library versions. These versions contained Trojans that, upon user execution, would exfiltrate sensitive data like cloud credentials, SSH keys, API tokens, database passwords, and environment variable configurations to the attackers' command and control (C2) server.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (10)
All FileHash-MD5 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3ee893ae46530b92e0d26435fb979d82 2026-04-26
FileHash-MD5 484067fd6232f7cdd7b664b33857fc2c 2026-04-26
FileHash-MD5 971670c10eff28339a085ca50a600e35 2026-04-26
FileHash-MD5 9b3257e45b27a6bbe4e240e41a3a306f 2026-04-26
FileHash-MD5 c6ce4e25f7fe3e3bb1eea2e9052483bf 2026-04-26
FileHash-MD5 e291734d46c313a23d676681499f8846 2026-04-26
FileHash-SHA256 077d49fa708f498969d7cdffe701eb64675baaa4968ded9bd97a4936dd56c21c 2026-04-26
FileHash-SHA256 e1e007ce4eab7774785617179d1c01a9381ae83abfd431aae8dba6f82d3ac127 2026-04-26
URL https://whereisitat.lucyatemysuperbox.space 2026-04-26
hostname whereisitat.lucyatemysuperbox.space 2026-04-26