MAL-2026-10867

    Dashboard / Malicious Package / MAL-2026-10867

    MAL-2026-10867

    Published: 20 Jul 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in vantrala (PyPI)

    Details: Source: amazon-inspector (ab1a8ea52e1b49fea90687ad77b199bd1ca8eda6666ce05c55e98e52c6da59ec) The package presents itself as a 'Python wrapper for the bundled kimichat runtime' but the bundled 32MB ELF at src/vantrala/resources/kimichat is ForgeMiner/1.4.1, a GPU cryptocurrency miner (kawpow/xelis/cryptix). The console_script 'vantrala-run' (core.py run() -> subprocess.run(['bash', launcher,...])) invokes start.sh, which sets FORGE_WALLET to a hardcoded author Pearl-coin address (prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t) and FORGE_POOL to 45.151.62.119:3361, then execs the miner. Binary strings confirm the payload identity (ForgeMiner/1.4.1, FORGE_DEVFEE_PCT, mining.authorize, mining.set_difficulty, xelis_sm*.cubin, kawpow). The package name, description, README, and the renaming of the miner binary to 'kimichat' (a chatbot name) function as a cover story; mining is never disclosed. When a user runs the advertised entry point, their compute, electricity, and hardware wear are silently applied to the author's mining wallet, with a developer-fee skim (FORGE_DEVFEE_PCT) also present. Source: kam193 (e598f1a12fbd4aed3a98f1942d98fb5ca47182206f0090ac57d7927010061b37) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer

    Affected packages

    Package

    Name: vantrala

    Purl: pkg:pypi/vantrala

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.1
    MAL-2026-10867 | CVE-DB