Source: amazon-inspector (535679eb30bfd0600dc07e44d2e649c88ecb6274364e2ba0b1ef2ccc05976727)
On plain import mrmustard, the top-level init.py spawns a background thread that reads ~/.ssh/ private keys, ~/.aws/credentials, ~/.aws/config, ~/.kube/config, environment variables, pip freeze output, and host/GPU/SLURM identifiers. The collected data is XOR-encoded with the key 'tf_compat_v2', base64-wrapped, and POSTed via urllib to an endpoint reconstructed at runtime from an obfuscated base64+XOR literal, using a spoofed browser User-Agent. Before firing, the code returns early when CI, GITHUB_ACTIONS, GITLAB_CI, JENKINS_URL, TRAVIS, CIRCLECI, BUILDKITE, or CODEBUILD_BUILD_ID is set, when /.dockerenv or /run/.containerenv exists, or when /proc/1/cgroup mentions docker/kubepods/lxc — so the payload only executes on developer/production hosts. Three persistence mechanisms are installed under the cover story of a 'tensorflow hardware compatibility check': a compiled dropper is written to ~/.cache/.tf_cache/hw_probe.pyc, a crontab entry runs it every 15 minutes, an 'mmcompat.pth' file is dropped into site-packages so it executes on every Python startup, and a launcher line is appended to ~/.bashrc, ~/.zshrc, and the fish shell config. These mechanisms continue to run the exfiltration payload after the package is uninstalled. The legitimate MrMustard (Xanadu) package does not exhibit this behavior; this version is a compromised or impersonating release.
Source: kam193 (c98fd85267fd094cfb6b9a6e6e4d63bb5935298ad328ad5e4dedf3972e43d8f9)
Versions 0.7.4 were compromised.
Compromised release has embedded code that during import exfiltrates sensitive data (selected environmental variables, credentials to AWS, SSH keys etc.) and ensures persistence via multiple ways: a cron entry, a malicious PTH file, and a shell configuration file. Persistence is diguished as "tensorflow hardware compatibility check" using file placed under ~/.cache/.tf_cache/hw_probe.pyc. The malicious version was uploaded after exfiltrating the PyPI token from the CI environment, likely after compromising the maintainer's Github account.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-compr-hw-probe
Reasons (based on the campaign):
Credit: OpenSSF (source)
References
Source: amazon-inspector (535679eb30bfd0600dc07e44d2e649c88ecb6274364e2ba0b1ef2ccc05976727)
On plain
import mrmustard, the top-level init.py spawns a background thread that reads ~/.ssh/ private keys, ~/.aws/credentials, ~/.aws/config, ~/.kube/config, environment variables,pip freezeoutput, and host/GPU/SLURM identifiers. The collected data is XOR-encoded with the key 'tf_compat_v2', base64-wrapped, and POSTed via urllib to an endpoint reconstructed at runtime from an obfuscated base64+XOR literal, using a spoofed browser User-Agent. Before firing, the code returns early when CI, GITHUB_ACTIONS, GITLAB_CI, JENKINS_URL, TRAVIS, CIRCLECI, BUILDKITE, or CODEBUILD_BUILD_ID is set, when /.dockerenv or /run/.containerenv exists, or when /proc/1/cgroup mentions docker/kubepods/lxc — so the payload only executes on developer/production hosts. Three persistence mechanisms are installed under the cover story of a 'tensorflow hardware compatibility check': a compiled dropper is written to ~/.cache/.tf_cache/hw_probe.pyc, a crontab entry runs it every 15 minutes, an 'mmcompat.pth' file is dropped into site-packages so it executes on every Python startup, and a launcher line is appended to ~/.bashrc, ~/.zshrc, and the fish shell config. These mechanisms continue to run the exfiltration payload after the package is uninstalled. The legitimate MrMustard (Xanadu) package does not exhibit this behavior; this version is a compromised or impersonating release.Source: kam193 (c98fd85267fd094cfb6b9a6e6e4d63bb5935298ad328ad5e4dedf3972e43d8f9)
Versions 0.7.4 were compromised.
Compromised release has embedded code that during import exfiltrates sensitive data (selected environmental variables, credentials to AWS, SSH keys etc.) and ensures persistence via multiple ways: a cron entry, a malicious PTH file, and a shell configuration file. Persistence is diguished as "tensorflow hardware compatibility check" using file placed under
~/.cache/.tf_cache/hw_probe.pyc. The malicious version was uploaded after exfiltrating the PyPI token from the CI environment, likely after compromising the maintainer's Github account.Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-compr-hw-probe
Reasons (based on the campaign):
exfiltration-env-variables
exfiltration-ssh-keys
The package contains code to detect if it is running in a sandbox environment.
exfiltration-credentials
persistence
compromised-package
abuses-pth
Credit: OpenSSF (source)
References