PULSE NAME
Supply Chain Poisoning via PyPI Repository Compromise
WHITE AlienVault 2026-04-27 Modified: 2026-04-27
10
IOCs
LOW VOLUME
Xinference, an open-source distributed AI model inference framework, suffered a supply chain attack when attackers compromised PyPI release credentials of maintainers and published three malicious versions (2.6.0, 2.6.1, 2.6.2) on April 22, 2026. The malicious code, encoded in Base64 layers within __init__.py, executes automatically upon library installation or import, collecting cloud credentials, SSH keys, API tokens, database passwords, cryptocurrency wallets, and environment variables. The payload specifically targets AWS environments through metadata service exploitation and uploads stolen data to attacker-controlled infrastructure. The attack affects users who downloaded these versions from PyPI, which has over 680,000 total downloads. Attribution remains unclear as TeamPCP's name appears in the code but the group denies involvement, suggesting third-party impersonation.
Indicators of Compromise (6 / 10 total)
All FileHash-MD5 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3ee893ae46530b92e0d26435fb979d82 2026-04-27
FileHash-MD5 484067fd6232f7cdd7b664b33857fc2c 2026-04-27
FileHash-MD5 971670c10eff28339a085ca50a600e35 2026-04-27
FileHash-MD5 9b3257e45b27a6bbe4e240e41a3a306f 2026-04-27
FileHash-MD5 c6ce4e25f7fe3e3bb1eea2e9052483bf 2026-04-27
FileHash-MD5 e291734d46c313a23d676681499f8846 2026-04-27