Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Part of a larger attack: 2026-07-kimichat published 8 malicious packages. See the full campaign →
Malicious package

fluffy-octo-broccoliPyPI

fluffy-octo-broccoli is a confirmed malicious PyPI package (MAL-2026-10973) that steals credentials and exfiltrates sensitive data (malicious version 0.1.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in fluffy-octo-broccoli (PyPI)

MAL-2026-10973
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall fluffy-octo-broccoli

What this malware does

fluffy-octo-broccoli ships a 10.7 MB qiwi.zip archive whose contents yield no readable filenames or strings via extraction, alongside a run.sh that unzips the archive in the current working directory, chmods start.sh executable, and runs it. The package's console-script entry (launcher.py) invokes bash run.sh via subprocess. The README's only stated purpose is 'Runs the bundled startup script when installed,' with no description of what the executed shell payload actually does. The archive's opacity prevents any inspection of the code that will run when the CLI is invoked. Execution is not automatic on pip install — the user must invoke the console script — but once invoked, the executed shell content is completely undocumented and unverifiable.

In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-kimichat

Reasons (based on the campaign):

  • cryptominer

Malicious versions

1 flagged
0.1.0

Indicators of compromise (SHA-256)

ed721bd4c1baf8e69a7f3c5039ac5644b8c6f0795e87fc711d3cd2b0a523c1e1
b017d48fb884ba615e0b62dfd421f8fe24e52695a7ae86c8c158eb2ded44286f

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for fluffy-octo-broccoli (version 0.1.0). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging fluffy-octo-broccoli across your stack and pipelines.

  2. If you installed it — respond

    fluffy-octo-broccoli is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If fluffy-octo-broccoli was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks fluffy-octo-broccoli before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. fluffy-octo-broccoli on PyPI has been identified as a malicious package (version 0.1.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-07-kimichatIN-MAL-2026-012891

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks fluffy-octo-broccoli-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

fluffy-octo-broccoli (PyPI) malicious package — MAL-2026-10973 | O3 Security