-= Per source details. Do not edit below this line.=-
animated-octo-spoon 0.1.0 ships a 2.6MB Linux ELF binary named 'forge' (a Rust-compiled CUDA GPU miner) plus a launcher script start.sh. The package's PyPI CLI entrypoint chmods and executes the bundled binary, which connects to the hardcoded mining pool at 45.151.62.119:3361 and submits shares to the hardcoded author wallet prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t via the stratum protocol (mining.subscribe / mining.authorize). The binary calls NVML and CUDA APIs (nvmlDeviceSetPowerManagementLimit, cuMemcpyHtoD_v2) to drive the installer's GPU. The pyproject description advertises the package as 'A simple Python installer program' and the README does not mention cryptocurrency mining; only the keywords hint at it. When the operator invokes the advertised CLI, the installer's GPU compute and electricity are silently routed to the author's wallet.
In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-kimichat
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"id": "pypi/2026-07-kimichat/animated-octo-spoon",
"import_time": "2026-07-21T16:33:26.317963777Z",
"modified_time": "2026-07-21T15:24:17.282057Z",
"sha256": "52fb3a0200c7b61bf5fc682f4d07d707c8793eff868ee0d2877de539bddd62b2",
"source": "kam193",
"versions": [
"0.1.0",
"0.1.1"
]
},
{
"id": "IN-MAL-2026-011268",
"import_time": "2026-08-04T22:30:08.19978017Z",
"modified_time": "2026-08-04T21:56:42Z",
"sha256": "9c54ed87d7e17e6be9f6e7c22f4f008e7a6326253127248f2c14f8a19390ac31",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-011158",
"import_time": "2026-08-04T22:30:02.35713873Z",
"modified_time": "2026-08-04T21:40:52Z",
"sha256": "f397205e8238a63da60096c8192b82ddbe9066fc9e5943b723775cddb6206e3f",
"source": "amazon-inspector",
"versions": [
"0.1.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "animated_octo_spoon/start.sh",
"sha256": "01b4536470a22202903ec9bcc79e66413e11b47614e7a1d81c5b84449f96933f",
"tlsh": "473163c7bd0402315519bb283d0278ce6e5820b75a8b3159bbcc77b1930ffa449238f2"
},
{
"path": "animated_octo_spoon/forge",
"sha256": "4afb125a337c00aa24f05dd508795ca4132557088a2d05937be7e5ecf4721d81",
"tlsh": "bdc5e013f6315098d9a6c434839ea273e721fc4953246ae72bd4ab202f65fe09f3db51"
}
],
"package_integrity": [
{
"filename": "animated_octo_spoon-0.1.0-py3-none-any.whl",
"hashes": {
"blake2b_256": "f23ff1072f879c606b54a11ca3c41369970b570254cf075a0f7157af0b96ff2b",
"md5": "ac67f638c1c125a5f6c6153ce72875c5",
"sha256": "7bab3dec22b33dece529583a1f5ebe59bde8cc282066bd689f927dda2ce50711"
}
},
{
"filename": "animated_octo_spoon-0.1.0.tar.gz",
"hashes": {
"blake2b_256": "297752822e4b5d8ad64fdee2ed81d9354dadecf948a64c177effb1e05042861b",
"md5": "2e16662f9bcc5135f351a9124261fd21",
"sha256": "1245c45eab0775dca75efc42634182381adf8de474ee836abc635619b5364e93"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/animated-octo-spoon/MAL-2026-10985.json"