MAL-2026-10867
Dashboard / Malicious Package / MAL-2026-10867
MAL-2026-10867
Summary: Malicious code in vantrala (PyPI)
Details: Source: amazon-inspector (ab1a8ea52e1b49fea90687ad77b199bd1ca8eda6666ce05c55e98e52c6da59ec) The package presents itself as a 'Python wrapper for the bundled kimichat runtime' but the bundled 32MB ELF at src/vantrala/resources/kimichat is ForgeMiner/1.4.1, a GPU cryptocurrency miner (kawpow/xelis/cryptix). The console_script 'vantrala-run' (core.py run() -> subprocess.run(['bash', launcher,...])) invokes start.sh, which sets FORGE_WALLET to a hardcoded author Pearl-coin address (prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t) and FORGE_POOL to 45.151.62.119:3361, then execs the miner. Binary strings confirm the payload identity (ForgeMiner/1.4.1, FORGE_DEVFEE_PCT, mining.authorize, mining.set_difficulty, xelis_sm*.cubin, kawpow). The package name, description, README, and the renaming of the miner binary to 'kimichat' (a chatbot name) function as a cover story; mining is never disclosed. When a user runs the advertised entry point, their compute, electricity, and hardware wear are silently applied to the author's mining wallet, with a developer-fee skim (FORGE_DEVFEE_PCT) also present. Source: kam193 (e598f1a12fbd4aed3a98f1942d98fb5ca47182206f0090ac57d7927010061b37) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer
References: https://bad-packages.kam193.eu/pypi/package/vantrala, https://github.com/newbroughblueogwin/automatic-octo-invention, https://pypi.org/project/vantrala/0.1.1/
Affected packages
Package
Name: vantrala
Purl: pkg:pypi/vantrala
Affected ranges
Type: N/A
Events:
