MAL-2026-10865
Dashboard / Malicious Package / MAL-2026-10865
MAL-2026-10865
Summary: Malicious code in kimitalk (PyPI)
Details: Source: amazon-inspector (94983bf77f2b110f03fdd52385dfc4d215ad082666b1ac482c805062605c8d35) The package presents itself as a 'Kimi' chat runtime but bundles a 32MB ELF binary at resources/kimichat that is ForgeMiner 1.4.1, a CUDA GPU cryptominer supporting KawPow/Pearl/Xelis/Cryptix algorithms (embedded strings include 'ForgeMiner/1.4.1', 'mining.authorize', 'mining.subscribe', 'pearl.set_mining'). The kimitalk-run console_script defined by the package invokes core.py's run(), which executes subprocess.run(['bash', str(launcher),...]) against a bundled start.sh. start.sh exports FORGE_WALLET=prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t and POOL=45.151.62.119:3361 and then chmods and executes./kimitalk, directing the installer's GPU/CPU compute to a Pearl (PRL) payout address controlled by the package author via a Stratum pool at 45.151.62.119:3361. The advertised chat-runtime purpose is a cover story; the actual behavior converts the installer's hardware and electricity into cryptocurrency for the author with no in-package mechanism for the user to redirect payout. Source: kam193 (f48f2e540e85a647f55ad2b8758c8cca9d9a6105a72058870e59d4a410c83c9f) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer
References: https://bad-packages.kam193.eu/pypi/package/kimitalk, https://github.com/newbroughblueogwin/automatic-octo-invention, https://pypi.org/project/kimitalk/0.1.2/, https://pypi.org/project/kimitalk/0.1.0/, https://pypi.org/project/kimitalk/0.1.1/
Affected packages
Package
Name: kimitalk
Purl: pkg:pypi/kimitalk
Affected ranges
Type: N/A
Events:
