Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Part of a larger attack: 2026-07-kimichat published 8 malicious packages. See the full campaign →
Malicious package

kimitalkPyPI

kimitalk is a confirmed malicious PyPI package (MAL-2026-10865) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.0, 0.1.1, 0.1.2). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in kimitalk (PyPI)

MAL-2026-10865
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall kimitalk

What this malware does

The package presents itself as a 'Kimi' chat runtime but bundles a 32MB ELF binary at resources/kimichat that is ForgeMiner 1.4.1, a CUDA GPU cryptominer supporting KawPow/Pearl/Xelis/Cryptix algorithms (embedded strings include 'ForgeMiner/1.4.1', 'mining.authorize', 'mining.subscribe', 'pearl.set_mining'). The kimitalk-run console_script defined by the package invokes core.py's run(), which executes subprocess.run(['bash', str(launcher),...]) against a bundled start.sh. start.sh exports FORGE_WALLET=prl1p2jan4dvkdfkt5r3pra7z96axrxjyjcgat9w7ldetlcy9wffm569sc9ux2t and POOL=45.151.62.119:3361 and then chmods and executes./kimitalk, directing the installer's GPU/CPU compute to a Pearl (PRL) payout address controlled by the package author via a Stratum pool at 45.151.62.119:3361. The advertised chat-runtime purpose is a cover story; the actual behavior converts the installer's hardware and electricity into cryptocurrency for the author with no in-package mechanism for the user to redirect payout.

In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-kimichat

Reasons (based on the campaign):

  • cryptominer

Malicious versions

3 flagged
0.1.00.1.10.1.2

Indicators of compromise (SHA-256)

f48f2e540e85a647f55ad2b8758c8cca9d9a6105a72058870e59d4a410c83c9f
b0bf13b40cfd82ba1c3a7212b86371b6708168dff820573dcafec926a2956545
457a29dcd199162d8ddf57e8b0e4de200a980ab80cee881e46952965aa8861b9
86975a0832868cd75811cc38c1c0b9158c4ecf4344e2e37f41c98cf87837af1a
94983bf77f2b110f03fdd52385dfc4d215ad082666b1ac482c805062605c8d35

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for kimitalk (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging kimitalk across your stack and pipelines.

  2. If you installed it — respond

    kimitalk is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If kimitalk was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks kimitalk before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. kimitalk on PyPI has been identified as a malicious package (versions 0.1.0, 0.1.1, 0.1.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-07-kimichatIN-MAL-2026-011114IN-MAL-2026-011256IN-MAL-2026-011159

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks kimitalk-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

kimitalk (PyPI) malicious package — MAL-2026-10865 | O3 Security