top of page
perceptive_background_267k.jpg

TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package

Published:

23 April 2026 at 19:04:59

Alert date:

23 April 2026 at 20:03:43

Source:

stepsecurity.io

Click to open the original link from this advisory

Supply Chain & Dependencies, Ransomware & Malware

TeamPCP threat actor injected a two-stage credential stealer into the xinference PyPI package, compromising the software supply chain. This attack targets developers and users who install the malicious package, potentially stealing credentials and sensitive information. The malware operates in two stages, likely to evade detection and maximize data collection. This represents a significant supply chain security incident affecting the Python ecosystem. Organizations using xinference package should immediately assess their exposure and update to clean versions.

Technical details

Mitigation steps:

Affected products:

xinference
PyPI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page