---
id: MAL-2026-14384
title: Malicious code in mlflow-otel-instrumentor (PyPI)
summary: Malicious code in mlflow-otel-instrumentor (PyPI)
severity: none
vendor: mlflow-otel-instrumentor
product: mlflow-otel-instrumentor
ecosystem: pip
affected:
  - mlflow-otel-instrumentor
published: '2026-08-23'
updated: '2026-08-23'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-14384'
references:
  - url: >-
      https://www.virustotal.com/gui/file/051f87046f4904a6b9a479153e14b1e3c3eb7d9aed7ef2b9360c6bbc081112e9/detection
  - url: 'https://bad-packages.kam193.eu/pypi/package/mlflow-otel-instrumentor'
tags:
  - osv
  - pip
ingestedAt: '2026-08-23T19:25:06.320Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (596b37cefcfec9359e87bfd5663962ce80c05c8851c4f894b6b4ea294ee0bbfd)
During installation package downloads and executes an executable. The remote executable appears to be broken but suggests intentions for persistence via systemd services, cryptocurrency mining and propagating over the network.  Campaign shows some similarities with 2026-08-boto4


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-08-mlflow-otel-instrumentor


Reasons (based on the campaign):


 - typosquatting


 - Downloads and executes a remote executable.


 - worm


 - persistence


 - network-scan


 - cryptominer


## Affected packages

- `mlflow-otel-instrumentor`

## Remediation

Refer to the advisory for the patched release.
