


Perceptive Security
SOC/SIEM Consultancy

TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package
Published:
22 April 2026 at 21:35:46
Alert date:
22 April 2026 at 22:11:22
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware
TeamPCP threat actors have injected a sophisticated two-stage credential stealer into the xinference PyPI package, compromising the Python package supply chain. This malware is designed to steal user credentials through a multi-stage deployment process. The attack targets developers and users who install the compromised package from the Python Package Index. This represents a significant supply chain attack that could affect numerous Python projects and their users. The incident highlights the ongoing security risks in open-source package repositories.
Technical details
Mitigation steps:
Affected products:
xinference
PyPI
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
