MAL-2026-10864

    Dashboard / Malicious Package / MAL-2026-10864

    MAL-2026-10864

    Published: 20 Jul 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in kimichat (PyPI)

    Details: Source: amazon-inspector (b57c88bce76fccb6cb2b3a99ef53a62402a8d56b4918ba4c7f2b634036317093) The package presents itself as a 'Python wrapper for the bundled kimichat runtime' and exposes a `kimichat-run` console script plus `kimichat.run()`. Invoking either causes `kimichat.core.run()` to spawn `bash` on the bundled `src/kimichat/resources/start.sh`, which chmod+x's and executes a ~32MB bundled Linux ELF at `src/kimichat/resources/kimichat`. String analysis of the ELF identifies it as 'ForgeMiner/1.4.1', a stratum GPU miner with CUDA kernels for kawpow/xelis/kryptix/alpha/keryx and standard stratum verbs (`mining.authorize`, `mining.subscribe`). `start.sh` hardcodes the mining destination and wallet: `FORGE_WALLET="prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t"` and `POOL="45.151.62.119:3361"`. Running the tool consumes the host's GPU and electricity and routes the mined rewards to the hardcoded author wallet; the delivered binary does not match the package's advertised purpose as a chat runtime. Source: kam193 (1d4795d0466af3e087dba2ac688463000092f9f4fda9040a4653956a3dc2583a) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer

    Affected packages

    Package

    Name: kimichat

    Purl: pkg:pypi/kimichat

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    0.1.1