A new malicious package discovered on the Python Package Index (PyPI) has been found to mimic a popular library for symbolic mathematical analysis, with the aim of installing malicious payloads, including the XMRig Miner, on Linux hosts.
See also: Malicious PyPI soopsocks package infected 2,653 systems

The package, called sympy-dev, mimics SymPy, replicating the latter's project description verbatim in an attempt to trick unsuspecting users into believing they are downloading a "development version" of the library. It has been downloaded over 1,100 times since it was first published on January 17, 2026.
Although the number of downloads is not a reliable measure for estimating the number of infections, the quantity probably suggests that some developers may have fallen victim to the malicious campaign. The package remains available for download for now.
According to Socket, the original library has been modified to act as a downloader for the XMRig miner on compromised systems. The malicious behavior is designed to only be triggered when specific polynomial routines are called, so it remains invisible.
See also: New Phishing Attack Targets PyPI Administrators

“When activated, the backdoored functions retrieve a remote JSON configuration, download an ELF payload controlled by the threat actor, and execute it from an anonymous memory-backed file pointer using Linux memfd_create and /proc/self/fd, which shrinks files to disk,” security researcher Kirill Boychenko in a Wednesday analysis.
The modified functions are used to execute a downloader, which retrieves a remote JSON configuration and an ELF payload from “63.250.56[.]54,” and then launches the ELF binary along with the configuration as input directly into memory to avoid touching the files on disk. This technique has been previously adopted by cryptojacking campaigns organized by FritzFrog and Mimo.
See also: AI Villager tool reaches 11,000 downloads on PyPI

The ultimate goal of the attack is to download two Linux ELF binaries designed to mine cryptocurrency using XMRig on Linux hosts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
