TI Mindmap HUB
Threat Intelligence Report

Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials

๐Ÿ“… July 26, 2026 ๐Ÿ“ฐ www.stepsecurity.io ๐Ÿ” 0 CVE(s) referenced

A compromised maintainer account published a malicious version of the mrmustard PyPI package (0.7.4) that, when imported, stealthily exfiltrates SSH, AWS, and Kubernetes credentials, installs multiple persistence mechanisms, and targets developer and research machines, making immediate remediation and credential rotation critical.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle