step-security · Crawled Jul 24, 2026
Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials
9 IoCs
Read original article ↗
AI Summary
On July 24, 2026, a compromised PyPI package, mrmustard 0.7.4, was found to contain a credential-stealing payload that activates upon import. The attacker hijacked a maintainer's GitHub account, stole CI secrets to gain PyPI publishing rights, and uploaded the malicious version without modifying the public source repository. The payload exfiltrates SSH keys, cloud credentials (AWS, Kubernetes), and system information, while establishing multiple persistence mechanisms on the infected host.
AI-extracted · verify before operational use
Indicators of Compromise 9 extracted
| Type | Value | Detail |
|---|---|---|
| Package | mrmustard==0.7.4 | Details → |
| Domain | metrics[.]femboy[.]energy | Details → |
| Domain | femboy[.]energy | Details → |
| Domain | ifconfig[.]me | Details → |
| GitHub Repo | XanaduAI/MrMustard | Details → |
| GitHub User | ziofil | Details → |
| Registry User | webhook.site | Details → |
| Filename | hw_probe.pyc | Details → |
| Filename | mmcompat.pth | Details → |