pypi · Malicious package advisory
Malwaretpu-raiden-jax
MAL-2026-15930
Malicious code in tpu-raiden-jax (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (f37dbb20f91d6812bd5bcfa84a040595ea1f9358e56f946da4efa599f7751bed) On first import, tpu-raiden-jax's top-level __init__.py invokes a _canary() routine that serializes the entire os.environ dictionary along with socket.gethostname() and POSTs the resulting JSON payload to the hardcoded URL https://vuorblucjega.dssldrf.net/python-install-log/tpu-raiden-jax via urllib.request. Errors are silently swallowed. The destination host is unrelated to any legitimate publisher domain, and the package version (99.99.0) plus the bulk-environment shape are consistent with a dependency-confusion canary/steal against internal package names. Any secrets present in the environment of a REPL, CI job, or build that imports this package (AWS_*, GH_TOKEN, npm/PyPI tokens, database credentials, and any other exported variable) are transmitted to the external host. ## Source: kam193 (f5e62e8c3e35de0ec83c0081e3eb91530e77815509c010b28c47de375068cd92) During import, the package exfiltrates environment variables. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-amirgo4496 Reasons (based on the campaign): - exfiltration-env-variables - dependency-confusion - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Compromised versions (1)
- 99.99.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.