ON July 24, 2026, the Python Package Index (PyPI) hosted a malicious version (0.7.4) of the mrmustard package, which steals SSH keys, AWS, and Kubernetes credentials upon import. This compromise resulted from a hijacked maintainer's GitHub account that executed a series of steps, including the exfiltration of publishing tokens and inserting malicious code into the package. The attack's implications emphasize the need for immediate credential rotation and removal of persistence mechanisms installed by the malware.
Steps for identifying affected environments and recovering from the attack are detailed, along with measures to protect against such threats, all supported by StepSecurity's detection capabilities.