Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials
PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.
- Disclosed
- Last updated
- Blast radius
- All users who installed mrmustard version 0.7.4 from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- mrmustard · 0.7.4
mrmustard 0.7.4 on PyPI contained malicious code designed to exfiltrate sensitive credentials. The attack executed automatically on package import, targeting SSH keys, AWS credentials, and Kubernetes configuration files.\n\nThe malicious payload was embedded in the package and would run without explicit user action, making it a particularly dangerous supply chain compromise. Any system that imported the affected version would have had credentials stolen and transmitted to attacker-controlled infrastructure.\n\nThe compromised version has been removed from PyPI. Users who installed mrmustard 0.7.4 should immediately rotate all affected credentials including SSH keys, AWS access keys, and Kubernetes tokens.
Indicators of compromise
- Packages
- mrmustard==0.7.4
Remediation
- Immediately uninstall mrmustard 0.7.4 from all systems
- Rotate all SSH keys that may have been exposed
- Rotate AWS access keys and secret keys
- Rotate Kubernetes service account tokens and credentials
- Review CloudTrail and other audit logs for unauthorized access using stolen credentials
- Update to a patched version of mrmustard from a trusted source after verification
- Scan systems for any persistence mechanisms or additional malware that may have been installed
Sources
Cite this entry
"Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 24, 2026; last updated July 24, 2026. https://supplychainattack.org/incident/compromised-pypi-package-mrmustard-0-7-4-steals-ssh-cloud-and-kubernetes-credent-1gt9v3
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in adv2099m2 (PyPI)
Malicious code was discovered in the adv2099m2 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in adminbypasser (PyPI)
Malicious code was published in the adminbypasser package on PyPI. The package silently downloads and executes remote code, establishing persistence via autostart mechanisms. The remote domain used by the malware no longer exists at the time of analysis.
PyPICompromised package - resolvedcritical
Malicious code in adpaypal (PyPI)
The adpaypal package on PyPI contained malicious code executing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adcv (PyPI)
The adcv package on PyPI contained malicious code as part of a campaign by the EsqueleSquad group. The group published nearly 6000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.
EsquelesquadPyPICompromised package