{"id":"MAL-2026-10985","summary":"Malicious code in animated-octo-spoon (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9c54ed87d7e17e6be9f6e7c22f4f008e7a6326253127248f2c14f8a19390ac31)\nanimated-octo-spoon 0.1.0 ships a 2.6MB Linux ELF binary named 'forge' (a Rust-compiled CUDA GPU miner) plus a launcher script start.sh. The package's PyPI CLI entrypoint chmods and executes the bundled binary, which connects to the hardcoded mining pool at 45.151.62.119:3361 and submits shares to the hardcoded author wallet prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t via the stratum protocol (mining.subscribe / mining.authorize). The binary calls NVML and CUDA APIs (nvmlDeviceSetPowerManagementLimit, cuMemcpyHtoD_v2) to drive the installer's GPU. The pyproject description advertises the package as 'A simple Python installer program' and the README does not mention cryptocurrency mining; only the keywords hint at it. When the operator invokes the advertised CLI, the installer's GPU compute and electricity are silently routed to the author's wallet.\n\n## Source: kam193 (52fb3a0200c7b61bf5fc682f4d07d707c8793eff868ee0d2877de539bddd62b2)\nIn this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-kimichat\n\n\nReasons (based on the campaign):\n\n\n - cryptominer\n","modified":"2026-08-04T23:05:48.401655660Z","published":"2026-07-21T15:24:17Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","versions":["0.1.0","0.1.1"],"id":"pypi/2026-07-kimichat/animated-octo-spoon","import_time":"2026-07-21T16:33:26.317963777Z","modified_time":"2026-07-21T15:24:17.282057Z","sha256":"52fb3a0200c7b61bf5fc682f4d07d707c8793eff868ee0d2877de539bddd62b2"},{"sha256":"9c54ed87d7e17e6be9f6e7c22f4f008e7a6326253127248f2c14f8a19390ac31","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-011268","import_time":"2026-08-04T22:30:08.19978017Z","modified_time":"2026-08-04T21:56:42Z"},{"versions":["0.1.1"],"id":"IN-MAL-2026-011158","import_time":"2026-08-04T22:30:02.35713873Z","modified_time":"2026-08-04T21:40:52Z","sha256":"f397205e8238a63da60096c8192b82ddbe9066fc9e5943b723775cddb6206e3f","source":"amazon-inspector"}]},"references":[{"type":"WEB","url":"https://github.com/newbroughblueogwin/automatic-octo-invention"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/animated-octo-spoon"},{"type":"PACKAGE","url":"https://pypi.org/project/animated-octo-spoon/0.1.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/animated-octo-spoon/0.1.1/"}],"affected":[{"package":{"name":"animated-octo-spoon","ecosystem":"PyPI","purl":"pkg:pypi/animated-octo-spoon"},"versions":["0.1.0","0.1.1"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"473163c7bd0402315519bb283d0278ce6e5820b75a8b3159bbcc77b1930ffa449238f2","path":"animated_octo_spoon/start.sh","sha256":"01b4536470a22202903ec9bcc79e66413e11b47614e7a1d81c5b84449f96933f"},{"tlsh":"bdc5e013f6315098d9a6c434839ea273e721fc4953246ae72bd4ab202f65fe09f3db51","path":"animated_octo_spoon/forge","sha256":"4afb125a337c00aa24f05dd508795ca4132557088a2d05937be7e5ecf4721d81"}],"package_integrity":[{"hashes":{"blake2b_256":"f23ff1072f879c606b54a11ca3c41369970b570254cf075a0f7157af0b96ff2b","md5":"ac67f638c1c125a5f6c6153ce72875c5","sha256":"7bab3dec22b33dece529583a1f5ebe59bde8cc282066bd689f927dda2ce50711"},"filename":"animated_octo_spoon-0.1.0-py3-none-any.whl"},{"filename":"animated_octo_spoon-0.1.0.tar.gz","hashes":{"blake2b_256":"297752822e4b5d8ad64fdee2ed81d9354dadecf948a64c177effb1e05042861b","md5":"2e16662f9bcc5135f351a9124261fd21","sha256":"1245c45eab0775dca75efc42634182381adf8de474ee836abc635619b5364e93"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/animated-octo-spoon/MAL-2026-10985.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}