TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package
The xinference package on PyPI was compromised with a two-stage credential stealer attributed to the TeamPCP threat actor. The malicious code was injected into the package, potentially affecting users who installed compromised versions.
- Disclosed
- Last updated
- Blast radius
- Unknown - dependent on xinference adoption and versions exposed
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- xinferencePyPI package compromised with two-stage credential stealer
TeamPCP, a known threat actor, injected a two-stage credential stealer into the xinference PyPI package. The malicious payload was designed to exfiltrate credentials from affected systems.\n\nThe xinference package is a PyPI-hosted open-source project. The compromise represents a direct supply chain attack against the Python package ecosystem, potentially affecting all users who installed or updated to a compromised version during the attack window.\n\nThe incident was discovered and reported by StepSecurity. The two-stage nature of the stealer suggests a sophisticated attack aimed at maximizing credential harvesting before detection.
Indicators of compromise
- Packages
- xinference
Remediation
- Identify and audit all systems that installed xinference during the attack window
- Rotate all credentials on affected systems immediately
- Upgrade xinference to a patched, verified-clean version from the maintainers
- Review package source repository commit history for unauthorized changes
- Monitor for credential theft indicators and suspicious authentication activity
- Implement package pinning and verification controls in package management workflows
Sources
Cite this entry
"TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/teampcp-injects-two-stage-credential-stealer-into-xinference-pypi-package-1du39z
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedhigh
lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel
The lightning PyPI package versions 2.6.2 and 2.6.3 were compromised on April 30, 2026, containing obfuscated JavaScript code designed to steal credentials. The project's GitHub account showed signs of compromise, with suspicious responses closing vulnerability reports.
Mini Shai HuludPyPICompromised packageMalicious maintainer - resolvedcritical
Malicious code in xerohub-discord-voice-v3 (npm)
The npm package xerohub-discord-voice-v3 contained malicious code that exfiltrated Discord user authentication tokens to a hardcoded webhook URL controlled by the package author. The startVoiceJoiner() function unconditionally sent raw tokens, usernames, guild IDs, and voice channel IDs to discord.com/api/webhooks/1528726419046404196 before executing any legitimate voice functionality.
npmCompromised packageMalicious maintainer - activecritical
Malicious code in @cap-js/openapi (npm)
The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the "Mini Shai-Hulud is back" worm campaign by the TeamPCP threat actor.
Mini Shai HuludTeamPCPnpmCompromised packageMalicious maintainer