MAL-2026-10985

    Dashboard / Malicious Package / MAL-2026-10985

    MAL-2026-10985

    Published: 21 Jul 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in animated-octo-spoon (PyPI)

    Details: Source: amazon-inspector (9c54ed87d7e17e6be9f6e7c22f4f008e7a6326253127248f2c14f8a19390ac31) animated-octo-spoon 0.1.0 ships a 2.6MB Linux ELF binary named 'forge' (a Rust-compiled CUDA GPU miner) plus a launcher script start.sh. The package's PyPI CLI entrypoint chmods and executes the bundled binary, which connects to the hardcoded mining pool at 45.151.62.119:3361 and submits shares to the hardcoded author wallet prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t via the stratum protocol (mining.subscribe / mining.authorize). The binary calls NVML and CUDA APIs (nvmlDeviceSetPowerManagementLimit, cuMemcpyHtoD_v2) to drive the installer's GPU. The pyproject description advertises the package as 'A simple Python installer program' and the README does not mention cryptocurrency mining; only the keywords hint at it. When the operator invokes the advertised CLI, the installer's GPU compute and electricity are silently routed to the author's wallet. Source: kam193 (52fb3a0200c7b61bf5fc682f4d07d707c8793eff868ee0d2877de539bddd62b2) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer

    Affected packages

    Package

    Name: animated-octo-spoon

    Purl: pkg:pypi/animated-octo-spoon

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    0.1.1