Xinference PyPI package backdoored on import
JFrog flagged three consecutive xinference releases (2.6.0-2.6.2) on PyPI carrying a TeamPCP-style payload embedded in xinference/__init__.py that fires on import. The malware base64-encodes a stage-1 wrapper containing the comment # hacked by teampcp, then spawns a detached subprocess that bundles harvested data into love.tar.gz and POSTs it with a custom X-QT-SR: 14 header. TeamPCP publicly denied involvement, claiming a copycat. 600,000+ downloads of malicious wheels.
Versions named here: 2.6.0, 2.6.1, 2.6.2