MAL-2026-983
Dashboard / Malicious Package / MAL-2026-983
MAL-2026-983
Summary: Malicious code in tensorflow-opt (PyPI)
Details: Source: kam193 (c2197ee3bfb727ff46f407a50a515013ad05c423bfe202eea90eb6b593f08b14) Package is likely a dependency confusion against some legitimate extension packages for TensorFlow but contains just cryptominers. When calling the "start" method, the cryptominer is copied from the package directory to the main TensorFlow installation dir, and the cryptomining for a hardcoded wallet starts. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-old-tensorflow-opt Reasons (based on the campaign): - impersonation - dependency-confusion - cryptominer
References: https://www.virustotal.com/gui/file/e8e775add50c67e1c6f6ca20db318f745e22b085afcbdf5634015e6ef91e8853/detection, https://www.virustotal.com/gui/file/402438684406d1e3b2d1d5629151259ad864ffc55c8e6ab176f4c47c543d4fee/detection, https://bad-packages.kam193.eu/pypi/package/tensorflow-opt
Affected packages
Package
Name: tensorflow-opt
Purl: pkg:pypi/tensorflow-opt
Affected ranges
Type: N/A
Events:
