MAL-2026-10985
Dashboard / Malicious Package / MAL-2026-10985
MAL-2026-10985
Summary: Malicious code in animated-octo-spoon (PyPI)
Details: Source: amazon-inspector (9c54ed87d7e17e6be9f6e7c22f4f008e7a6326253127248f2c14f8a19390ac31) animated-octo-spoon 0.1.0 ships a 2.6MB Linux ELF binary named 'forge' (a Rust-compiled CUDA GPU miner) plus a launcher script start.sh. The package's PyPI CLI entrypoint chmods and executes the bundled binary, which connects to the hardcoded mining pool at 45.151.62.119:3361 and submits shares to the hardcoded author wallet prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t via the stratum protocol (mining.subscribe / mining.authorize). The binary calls NVML and CUDA APIs (nvmlDeviceSetPowerManagementLimit, cuMemcpyHtoD_v2) to drive the installer's GPU. The pyproject description advertises the package as 'A simple Python installer program' and the README does not mention cryptocurrency mining; only the keywords hint at it. When the operator invokes the advertised CLI, the installer's GPU compute and electricity are silently routed to the author's wallet. Source: kam193 (52fb3a0200c7b61bf5fc682f4d07d707c8793eff868ee0d2877de539bddd62b2) In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-kimichat Reasons (based on the campaign): - cryptominer
References: https://github.com/newbroughblueogwin/automatic-octo-invention, https://bad-packages.kam193.eu/pypi/package/animated-octo-spoon, https://pypi.org/project/animated-octo-spoon/0.1.0/, https://pypi.org/project/animated-octo-spoon/0.1.1/
Affected packages
Package
Name: animated-octo-spoon
Purl: pkg:pypi/animated-octo-spoon
Affected ranges
Type: N/A
Events:
