Skip to content
XinferenceMAL-2026-3000

Malicious code in xinference (PyPI)

UnratedPublished Apr 22, 2026 · updated Jun 8, 2026

Source advisory

Affected versions

PackageAffectedFixed in
xinference
PyPI
<= 2.6.2No fix yet
Details and references

--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (1d006f6a08c959393160456d4ace221fd165b6d609fc8356ebfb041979aef93d) Versions 2.6.0, 2.6.1, 2.6.2 were compromised. Following a malicious pull request that exfiltrated sensitive data from the CI runner, three malicious PyPI releases were published. Infected releases contain code typical for TeamPCP actions that exfiltrates all kinds of sensitive data (credentials, env variables, SSH keys, cloud tokens, configuration files, shell histories, cryptowallets, data from secret managers...). Malicious action activates during importing the main package's module. TeamPCP denies their involvement. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-teampcp Reasons (based on the campaign): - exfiltration-env-variables - exfiltration-ssh-keys - obfuscation - exfiltration-cloud-tokens - exfiltration-crypto - exfiltration-credentials - compromised-package - exploited-ci-vulnerability

Severity from
no source yet

More Xinference advisories

All Xinference
DateAdvisory
Aug 21Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
CVE-2026-61539Critical10.0fixed in 2.7.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.