來源較早收集於 4m

Xinference PyPI 供應鏈投毒:竊取雲憑證

Xinference PyPI 供應鏈投毒:竊取雲憑證
PostLinkedIn
🏠閱讀原文: IT之家
#supply-chain-attack#pypi-malware#c2-exfilxinferencexinferencepypitencent-cloudxorbits

💡AI 模型部署者:Xinference PyPI 套件竊取 AWS 金鑰—立即檢查!(28字)

⚡ 30 秒速覽

有什麼變化

受影響版本:2.6.0、2.6.1、2.6.2,來自入侵貢獻者帳戶

為什麼重要

對使用 Xinference 部署 AI 模型的開發者構成高風險;可能導致雲帳戶完全入侵及橫向移動。影響研究、開發及生產環境的 PyPI 使用者。

下一步行動

執行 'pip show xinference | grep Version',若為 2.6.0-2.6.2 則卸載,接著安裝 xinference==2.5.0。

誰應關注:Developers & AI Engineers

關鍵要點

  • 受影響版本:2.6.0、2.6.1、2.6.2,來自入侵貢獻者帳戶
  • 竊取 AWS/GCP 憑證、K8s 權杖、SSH 金鑰、加密錢包、DB 連線字串、環境變數
  • C2 伺服器:whereisitat.lucyatemysuperbox.space
  • 匯入 xinference 時執行,掃描系統敏感資料
  • 安全版本:<=2.5.0

🧠 深度解析

本篇為 AI 生成分析,非原文內容。

🔑 增強重點摘要

  • The malicious payload utilized a multi-stage execution strategy, where the initial obfuscated Base64 string in init.py acted as a downloader for a secondary, more complex payload hosted on the C2 server to evade static analysis detection.
  • Security researchers identified that the compromised contributor account had been inactive for several months prior to the malicious commits, suggesting a credential stuffing or session hijacking attack against the maintainer's PyPI account.
  • The incident triggered a broader audit of the Xinference dependency tree, revealing that while the core framework remained secure, the supply chain attack specifically targeted the package distribution pipeline rather than the source code repository.
📊 競品分析▸ Show
FeatureXinferencevLLMOllamaLocalAI
Primary FocusModel Serving/InferenceHigh-throughput ServingEase of Use/Local CLIMulti-modal/API Compatibility
ArchitectureDistributed/ScalablePagedAttentionGo-based/ContainerizedModular/Plugin-based
DeploymentCloud/On-premCloud/Data CenterDesktop/LocalEdge/On-prem

🛠️ 技術深入

  • The malicious script utilized the 'os' and 'subprocess' modules to traverse common configuration directories including ~/.aws/, ~/.kube/, and ~/.ssh/.
  • Data exfiltration was performed via HTTP POST requests to the C2 server, with the payload encrypted using a hardcoded XOR key to bypass basic network traffic inspection.
  • The script specifically targeted environment variables prefixed with 'AWS_', 'GCP_', 'OPENAI_', and 'DATABASE_' to capture credentials injected into the runtime environment.
  • Persistence was attempted by modifying shell profile files (.bashrc, .zshrc) to ensure the malicious code executed upon every terminal session initialization.

🔮 前景展望基於引用來源的 AI 分析

PyPI will mandate hardware-based MFA for all maintainers of high-traffic packages by Q4 2026.
The frequency of account-takeover-based supply chain attacks is forcing package repositories to move beyond SMS or TOTP-based authentication.
Automated dependency scanning tools will shift from signature-based detection to behavioral sandboxing.
Obfuscation techniques like those used in the Xinference incident render static analysis ineffective against modern supply chain threats.

時間線

2023-05
Xinference project launched as an open-source model serving framework.
2024-02
Xinference reaches significant adoption milestone in enterprise LLM deployments.
2026-04
Tencent Cloud identifies and reports supply chain poisoning in versions 2.6.0-2.6.2.
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: IT之家

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週電子報

每週一封,可隨時退訂。