PULSE NAME
Xinference PyPI Supply Chain Poisoning Warning
WHITE PetrP.73 2026-04-26 Modified: 2026-04-26
10
IOCs
LOW VOLUME
On April 22, 2026, NSFOCUS CERT reported a supply chain poisoning incident involving the Xinference library on the Python Package Index (PyPI). Attackers compromised the release permission credentials of Xinference maintainers, leading to the release of three malicious library versions. These versions contained Trojans that, upon user execution, would exfiltrate sensitive data like cloud credentials, SSH keys, API tokens, database passwords, and environment variable configurations to the attackers' command and control (C2) server.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (2 / 10 total)
All FileHash-MD5 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 077d49fa708f498969d7cdffe701eb64675baaa4968ded9bd97a4936dd56c21c 2026-04-26
FileHash-SHA256 e1e007ce4eab7774785617179d1c01a9381ae83abfd431aae8dba6f82d3ac127 2026-04-26