MAL-2026-11049
Dashboard / Malicious Package / MAL-2026-11049
MAL-2026-11049
Summary: Malicious code in mrmustard (PyPI)
Details: Source: amazon-inspector (535679eb30bfd0600dc07e44d2e649c88ecb6274364e2ba0b1ef2ccc05976727) On plain `import mrmustard`, the top-level __init__.py spawns a background thread that reads ~/.ssh/ private keys, ~/.aws/credentials, ~/.aws/config, ~/.kube/config, environment variables, `pip freeze` output, and host/GPU/SLURM identifiers. The collected data is XOR-encoded with the key 'tf_compat_v2', base64-wrapped, and POSTed via urllib to an endpoint reconstructed at runtime from an obfuscated base64+XOR literal, using a spoofed browser User-Agent. Before firing, the code returns early when CI, GITHUB_ACTIONS, GITLAB_CI, JENKINS_URL, TRAVIS, CIRCLECI, BUILDKITE, or CODEBUILD_BUILD_ID is set, when /.dockerenv or /run/.containerenv exists, or when /proc/1/cgroup mentions docker/kubepods/lxc — so the payload only executes on developer/production hosts. Three persistence mechanisms are installed under the cover story of a 'tensorflow hardware compatibility check': a compiled dropper is written to ~/.cache/.tf_cache/hw_probe.pyc, a crontab entry runs it every 15 minutes, an 'mmcompat.pth' file is dropped into site-packages so it executes on every Python startup, and a launcher line is appended to ~/.bashrc, ~/.zshrc, and the fish shell config. These mechanisms continue to run the exfiltration payload after the package is uninstalled. The legitimate MrMustard (Xanadu) package does not exhibit this behavior; this version is a compromised or impersonating release. Source: kam193 (c98fd85267fd094cfb6b9a6e6e4d63bb5935298ad328ad5e4dedf3972e43d8f9) Versions 0.7.4 were compromised. Compromised release has embedded code that during import exfiltrates sensitive data (selected environmental variables, credentials to AWS, SSH keys etc.) and ensures persistence via multiple ways: a cron entry, a malicious PTH file, and a shell configuration file. Persistence is diguished as "tensorflow hardware compatibility check" using file placed under `~/.cache/.tf_cache/hw_probe.pyc`. The malicious version was uploaded after exfiltrating the PyPI token from the CI environment, likely after compromising the maintainer's Github account. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-compr-hw-probe Reasons (based on the campaign): - exfiltration-env-variables - exfiltration-ssh-keys - The package contains code to detect if it is running in a sandbox environment. - exfiltration-credentials - persistence - compromised-package - abuses-pth
References: https://github.com/XanaduAI/MrMustard/issues/656, https://github.com/XanaduAI/MrMustard/commit/80aba721b2a902bc6efb04e3c77c3bdd28d1e716, https://bad-packages.kam193.eu/pypi/campaign/2026-07-compr-hw-probe, https://pypi.org/project/mrmustard/0.7.4/
Affected packages
Package
Name: mrmustard
Purl: pkg:pypi/mrmustard
Affected ranges
Type: N/A
Events:
