CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Malicious PyPI Package sympy-dev Deploys XMRig Miner on Linux Hosts

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A malicious Python Package Index (PyPI) package named sympy-dev impersonates the legitimate SymPy library to deploy an XMRig cryptocurrency miner on Linux hosts. The package, which has been downloaded over 1,100 times since its publication on January 17, 2026, includes backdoored functions that trigger only when specific polynomial routines are called. The malicious payload is fetched from a remote server and executed in memory to avoid leaving disk artifacts. The campaign has been linked to techniques previously used by cryptojacking groups like FritzFrog and Mimo. The package remains available for download as of the report's publication.

Timeline

  1. 22.01.2026 12:04 1 articles · 23h ago

    Malicious PyPI Package sympy-dev Deploys XMRig Miner on Linux Hosts

    A malicious Python Package Index (PyPI) package named sympy-dev impersonates the legitimate SymPy library to deploy an XMRig cryptocurrency miner on Linux hosts. The package, which has been downloaded over 1,100 times since its publication on January 17, 2026, includes backdoored functions that trigger only when specific polynomial routines are called. The malicious payload is fetched from a remote server and executed in memory to avoid leaving disk artifacts. The campaign has been linked to techniques previously used by cryptojacking groups like FritzFrog and Mimo.

    Show sources

Information Snippets