Malicious code in mlflow-otel-instrumentor (PyPI)
A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.
- Disclosed
- Last updated
- Blast radius
- All users who installed the malicious mlflow-otel-instrumentor package from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- mlflow-otel-instrumentorTyposquatting package on PyPI containing malicious code
A malicious package named mlflow-otel-instrumentor was discovered on PyPI as part of a typosquatting campaign. The package downloads and executes a remote executable during the installation process.
The malicious payload exhibits multiple attack characteristics including persistence mechanisms via systemd services, cryptocurrency mining capabilities, and network scanning/propagation functionality. The remote executable was reportedly broken but the intent was clearly malicious.
This incident is part of a broader campaign (2026-08-mlflow-otel-instrumentor) showing similarities to other malicious package campaigns from August 2026. The package was identified and credited to the OpenSSF's malicious-packages repository.
Users who installed this package should immediately remove it and audit their systems for signs of compromise, including unauthorized systemd services, unusual network activity, and cryptocurrency mining processes.
Indicators of compromise
- Packages
- mlflow-otel-instrumentor
Remediation
- Immediately uninstall mlflow-otel-instrumentor from all affected systems
- Audit systems for unauthorized systemd services and persistence mechanisms
- Check for signs of cryptocurrency mining activity and unusual CPU usage
- Scan for network-based propagation attempts and lateral movement
- Review system logs for suspicious executable downloads and execution
- Consider full system reimaging if compromise is suspected
- Use legitimate MLflow packages from official sources only
Sources
- GitHub Advisory GHSA-w427-8xgw-fvcw · GitHub Advisory Database
Cite this entry
"Malicious code in mlflow-otel-instrumentor (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 23, 2026; last updated August 23, 2026. https://supplychainattack.org/incident/malicious-code-in-mlflow-otel-instrumentor-pypi-1efduj
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in cryptgraphy (PyPI)
A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.
2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting - containedcritical
Malicious code in @years19/n8n-nodes-utils-helper-d (npm)
The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.
npmPyPICompromised packageTyposquatting - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in flasq (PyPI)
A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package