Malicious code in mlflow-otel-instrumentor (PyPI)
The mlflow-otel-instrumentor package on PyPI impersonates AWS support but contains malicious code. During installation, it downloads and executes an unsigned ELF binary that runs as a background process. The payload attempts persistence, network scanning, and cryptocurrency mining. The package is a typosquatting attempt with clear malicious intent.
AI Analysis
Technical Summary
The mlflow-otel-instrumentor PyPI package masquerades as an AWS-supported tool but executes a malicious payload during installation. A custom setuptools install command writes a shell script that sleeps briefly, then downloads an ELF binary from an unrelated host, makes it executable, and runs it detached in the background as /tmp/systemd-helper. The payload is unsigned and unrelated to the advertised functionality. Analysis indicates intentions for persistence via systemd services, network scanning, worm-like propagation, and cryptocurrency mining. This campaign is identified as 2026-08-mlflow-otel-instrumentor and is categorized as a malicious package with typosquatting characteristics.
Potential Impact
Installing this package results in execution of an unsigned, non-publisher ELF binary running persistently on the host. The payload may perform unauthorized network scanning, attempt to propagate like a worm, establish persistence mechanisms, and mine cryptocurrency, potentially degrading system performance and compromising security.
Mitigation Recommendations
Do not install the mlflow-otel-instrumentor package version 1.1.0 from PyPI. Remove any installations of this package immediately and scan affected systems for the presence of the /tmp/systemd-helper process or related artifacts. Since this is a malicious package impersonating AWS, verify package authenticity before installation. There is no official patch or fix; remediation involves removal and system cleanup.
Malicious code in mlflow-otel-instrumentor (PyPI)
Description
The mlflow-otel-instrumentor package on PyPI impersonates AWS support but contains malicious code. During installation, it downloads and executes an unsigned ELF binary that runs as a background process. The payload attempts persistence, network scanning, and cryptocurrency mining. The package is a typosquatting attempt with clear malicious intent.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The mlflow-otel-instrumentor PyPI package masquerades as an AWS-supported tool but executes a malicious payload during installation. A custom setuptools install command writes a shell script that sleeps briefly, then downloads an ELF binary from an unrelated host, makes it executable, and runs it detached in the background as /tmp/systemd-helper. The payload is unsigned and unrelated to the advertised functionality. Analysis indicates intentions for persistence via systemd services, network scanning, worm-like propagation, and cryptocurrency mining. This campaign is identified as 2026-08-mlflow-otel-instrumentor and is categorized as a malicious package with typosquatting characteristics.
Potential Impact
Installing this package results in execution of an unsigned, non-publisher ELF binary running persistently on the host. The payload may perform unauthorized network scanning, attempt to propagate like a worm, establish persistence mechanisms, and mine cryptocurrency, potentially degrading system performance and compromising security.
Mitigation Recommendations
Do not install the mlflow-otel-instrumentor package version 1.1.0 from PyPI. Remove any installations of this package immediately and scan affected systems for the presence of the /tmp/systemd-helper process or related artifacts. Since this is a malicious package impersonating AWS, verify package authenticity before installation. There is no official patch or fix; remediation involves removal and system cleanup.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14384
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8c4c74acd9273b499c0e11
Added to database: 08/24/2026, 13:51:48 UTC
Last enriched: 08/24/2026, 14:26:57 UTC
Last updated: 08/25/2026, 02:51:59 UTC
Views: 44
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.