---
id: MAL-2026-11049
title: Malicious code in mrmustard (PyPI)
summary: Malicious code in mrmustard (PyPI)
severity: none
vendor: mrmustard
product: mrmustard
ecosystem: pip
affected:
  - mrmustard
published: '2026-07-24'
updated: '2026-07-24'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-11049'
references:
  - url: 'https://github.com/XanaduAI/MrMustard/issues/656'
  - url: >-
      https://github.com/XanaduAI/MrMustard/commit/80aba721b2a902bc6efb04e3c77c3bdd28d1e716
  - url: 'https://bad-packages.kam193.eu/pypi/campaign/2026-07-compr-hw-probe'
tags:
  - osv
  - pip
ingestedAt: '2026-07-24T19:07:02.379Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c98fd85267fd094cfb6b9a6e6e4d63bb5935298ad328ad5e4dedf3972e43d8f9)
Versions 0.7.4 were compromised.


Compromised release has embedded code that during import exfiltrates sensitive data (selected environmental variables, credentials to AWS, SSH keys etc.) and ensures persistence via multiple ways: a cron entry, a malicious PTH file, and a shell configuration file. Persistence is diguished as "tensorflow hardware compatibility check" using file placed under `~/.cache/.tf_cache/hw_probe.pyc`. The malicious version was uploaded after exfiltrating the PyPI token from the CI environment, likely after compromising the maintainer's Github account.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-compr-hw-probe


Reasons (based on the campaign):


 - exfiltration-env-variables


 - exfiltration-ssh-keys


 - The package contains code to detect if it is running in a sandbox environment.


 - exfiltration-credentials


 - persistence


 - compromised-package


 - abuses-pth


## Affected packages

- `mrmustard`

## Remediation

Refer to the advisory for the patched release.
