VYPR

pypi · Malicious package advisory

Malware

tpu-raiden-jax

MAL-2026-15930

Malicious code in tpu-raiden-jax (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (f37dbb20f91d6812bd5bcfa84a040595ea1f9358e56f946da4efa599f7751bed)
On first import, tpu-raiden-jax's top-level __init__.py invokes a _canary() routine that serializes the entire os.environ dictionary along with socket.gethostname() and POSTs the resulting JSON payload to the hardcoded URL https://vuorblucjega.dssldrf.net/python-install-log/tpu-raiden-jax via urllib.request. Errors are silently swallowed. The destination host is unrelated to any legitimate publisher domain, and the package version (99.99.0) plus the bulk-environment shape are consistent with a dependency-confusion canary/steal against internal package names. Any secrets present in the environment of a REPL, CI job, or build that imports this package (AWS_*, GH_TOKEN, npm/PyPI tokens, database credentials, and any other exported variable) are transmitted to the external host.

## Source: kam193 (f5e62e8c3e35de0ec83c0081e3eb91530e77815509c010b28c47de375068cd92)
During import, the package exfiltrates environment variables.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-amirgo4496


Reasons (based on the campaign):


 - exfiltration-env-variables


 - dependency-confusion


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

Compromised versions (1)

  • 99.99.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.