PULSE NAME
Supply Chain Poisoning via PyPI Repository Compromise
WHITE AlienVault 2026-04-27 Modified: 2026-04-27
10
IOCs
LOW VOLUME
Xinference, an open-source distributed AI model inference framework, suffered a supply chain attack when attackers compromised PyPI release credentials of maintainers and published three malicious versions (2.6.0, 2.6.1, 2.6.2) on April 22, 2026. The malicious code, encoded in Base64 layers within __init__.py, executes automatically upon library installation or import, collecting cloud credentials, SSH keys, API tokens, database passwords, cryptocurrency wallets, and environment variables. The payload specifically targets AWS environments through metadata service exploitation and uploads stolen data to attacker-controlled infrastructure. The attack affects users who downloaded these versions from PyPI, which has over 680,000 total downloads. Attribution remains unclear as TeamPCP's name appears in the code but the group denies involvement, suggesting third-party impersonation.
Indicators of Compromise (2 / 10 total)
All FileHash-MD5 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 077d49fa708f498969d7cdffe701eb64675baaa4968ded9bd97a4936dd56c21c 2026-04-27
FileHash-SHA256 e1e007ce4eab7774785617179d1c01a9381ae83abfd431aae8dba6f82d3ac127 2026-04-27