MAL-2026-10865

    Dashboard / Malicious Package / MAL-2026-10865

    MAL-2026-10865

    Published: 20 Jul 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in kimitalk (PyPI)

    Details: Source: amazon-inspector (94983bf77f2b110f03fdd52385dfc4d215ad082666b1ac482c805062605c8d35) The package presents itself as a 'Kimi' chat runtime but bundles a 32MB ELF binary at resources/kimichat that is ForgeMiner 1.4.1, a CUDA GPU cryptominer supporting KawPow/Pearl/Xelis/Cryptix algorithms (embedded strings include 'ForgeMiner/1.4.1', 'mining.authorize', 'mining.subscribe', 'pearl.set_mining'). The kimitalk-run console_script defined by the package invokes core.py's run(), which executes subprocess.run(['bash', str(launcher),...]) against a bundled start.sh. start.sh exports FORGE_WALLET=prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t and POOL=45.151.62.119:3361 and then chmods and executes./kimitalk, directing the installer's GPU/CPU compute to a Pearl (PRL) payout address controlled by the package author via a Stratum pool at 45.151.62.119:3361. The advertised chat-runtime purpose is a cover story; the actual behavior converts the installer's hardware and electricity into cryptocurrency for the author with no in-package mechanism for the user to redirect payout. Source: kam193 (f48f2e540e85a647f55ad2b8758c8cca9d9a6105a72058870e59d4a410c83c9f) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer

    Affected packages

    Package

    Name: kimitalk

    Purl: pkg:pypi/kimitalk

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    0.1.1
    0.1.2
    MAL-2026-10865 | CVE-DB