www.stepsecurity.io 7/24/2026, 3:47:49 PM · external

Malicious PyPI package mrmustard steals SSH, AWS, K8s keys

Malicious PyPI package mrmustard steals SSH, AWS, K8s keys
CyberSIXT Evidence Panel Source marked as original reporting

ON July 24, 2026, the Python Package Index (PyPI) hosted a malicious version (0.7.4) of the mrmustard package, which steals SSH keys, AWS, and Kubernetes credentials upon import. This compromise resulted from a hijacked maintainer's GitHub account that executed a series of steps, including the exfiltration of publishing tokens and inserting malicious code into the package. The attack's implications emphasize the need for immediate credential rotation and removal of persistence mechanisms installed by the malware.

Steps for identifying affected environments and recovering from the attack are detailed, along with measures to protect against such threats, all supported by StepSecurity's detection capabilities.

View full article

Article by CyberSIXT