MAL-2026-10985
Malicious code in animated-octo-spoon (PyPI)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (9c54ed87d7e17e6be9f6e7c22f4f008e7a6326253127248f2c14f8a19390ac31) animated-octo-spoon 0.1.0 ships a 2.6MB Linux ELF binary named 'forge' (a Rust-compiled CUDA GPU miner) plus a launcher script start.sh. The package's PyPI CLI entrypoint chmods and executes the bundled binary, which connects to the hardcoded mining pool at 45.151.62.119:3361 and submits shares to the hardcoded author wallet prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t via the stratum protocol (mining.subscribe / mining.authorize). The binary calls NVML and CUDA APIs (nvmlDeviceSetPowerManagementLimit, cuMemcpyHtoD_v2) to drive the installer's GPU. The pyproject description advertises the package as 'A simple Python installer program' and the README does not mention cryptocurrency mining; only the keywords hint at it. When the operator invokes the advertised CLI, the installer's GPU compute and electricity are silently routed to the author's wallet.
## Source: kam193 (52fb3a0200c7b61bf5fc682f4d07d707c8793eff868ee0d2877de539bddd62b2) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-kimichat
Reasons (based on the campaign):
- cryptominer
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for animated-octo-spoon (pip). Pin to a known-safe version or switch to an alternative.