MAL-2026-10864
Dashboard / Malicious Package / MAL-2026-10864
MAL-2026-10864
Summary: Malicious code in kimichat (PyPI)
Details: Source: amazon-inspector (b57c88bce76fccb6cb2b3a99ef53a62402a8d56b4918ba4c7f2b634036317093) The package presents itself as a 'Python wrapper for the bundled kimichat runtime' and exposes a `kimichat-run` console script plus `kimichat.run()`. Invoking either causes `kimichat.core.run()` to spawn `bash` on the bundled `src/kimichat/resources/start.sh`, which chmod+x's and executes a ~32MB bundled Linux ELF at `src/kimichat/resources/kimichat`. String analysis of the ELF identifies it as 'ForgeMiner/1.4.1', a stratum GPU miner with CUDA kernels for kawpow/xelis/kryptix/alpha/keryx and standard stratum verbs (`mining.authorize`, `mining.subscribe`). `start.sh` hardcodes the mining destination and wallet: `FORGE_WALLET="prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t"` and `POOL="45.151.62.119:3361"`. Running the tool consumes the host's GPU and electricity and routes the mined rewards to the hardcoded author wallet; the delivered binary does not match the package's advertised purpose as a chat runtime. Source: kam193 (1d4795d0466af3e087dba2ac688463000092f9f4fda9040a4653956a3dc2583a) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer
References: https://bad-packages.kam193.eu/pypi/package/kimichat, https://github.com/newbroughblueogwin/automatic-octo-invention, https://pypi.org/project/kimichat/0.1.0/, https://pypi.org/project/kimichat/0.1.1/
Affected packages
Package
Name: kimichat
Purl: pkg:pypi/kimichat
Affected ranges
Type: N/A
Events:
