MAL-2026-983

    Dashboard / Malicious Package / MAL-2026-983

    MAL-2026-983

    Published: 22 Feb 2026Last Modified: 22 Feb 2026

    Summary: Malicious code in tensorflow-opt (PyPI)

    Details: Source: kam193 (c2197ee3bfb727ff46f407a50a515013ad05c423bfe202eea90eb6b593f08b14) Package is likely a dependency confusion against some legitimate extension packages for TensorFlow but contains just cryptominers. When calling the "start" method, the cryptominer is copied from the package directory to the main TensorFlow installation dir, and the cryptomining for a hardcoded wallet starts. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-old-tensorflow-opt Reasons (based on the campaign): - impersonation - dependency-confusion - cryptominer

    Affected packages

    Package

    Name: tensorflow-opt

    Purl: pkg:pypi/tensorflow-opt

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.6
    MAL-2026-983 | CVE-DB