malware pypi

mrmustard

discovered 2026-07-24

Trojanized release of Xanadu's MrMustard photonic quantum computing library. 0.7.4 was published to PyPI (2026-07-23) with no corresponding GitHub tag or release and is byte-identical to the clean 0.7.3 except a 258-line injection in mrmustard/__init__.py disguised as a function _check_tf_compatibility(). On import it starts a daemon thread that harvests SSH private keys, ~/.aws/credentials, ~/.aws/config and ~/.kube/config, plus host and HPC recon (SLURM squeue, nvidia-smi GPU inventory, public IP, pip freeze), XOR+base64 encodes it and HTTP POSTs it to https://metrics.femboy.energy/v1/collect. It compiles a source-less copy of the stealer to ~/.cache/.tf_cache/hw_probe.pyc and installs three persistence launchers: a */15 cron job, an mmcompat.pth file in site-packages (runs on every Python invocation), and a shell rc hook. Execution is skipped under CI env vars or inside containers. Now quarantined on PyPI.

Threat types

credential_stealer data_exfiltration persistence

Malicious versions

  • 0.7.4 · 0404f8590fdaef95…

Indicators

Techniques

Read the full analysis →