Malicious PyPI Package Impersonates SymPy Deploys XMRig Miner on Linux Hosts

It has been revealed that a new malicious package in the Python Package Index (PyPI) poses as a well-known symbolic mathematics library in order to infect Linux machines with malicious payloads, such as a bitcoin miner.

The package, called sympy-dev, attempts to trick unsuspecting users into believing they are downloading a “development version” of the library by imitating SymPy and copying its project description exactly. Since its initial release on January 17, 2026, it has been downloaded more than 1,100 times.

The download count probably indicates that some developers may have been impacted by the malicious effort, even though it is not a trustworthy indicator of the quantity of infections. As of this writing, the package is still accessible for download.

On hacked systems, the original library has been altered to function as a downloader for an XMRig bitcoin miner, according to Socket. In order to evade detection read more about Malicious PyPI Package Impersonates SymPy Deploys XMRig Miner on Linux Hosts.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *