Supply Chain Poisoning via PyPI Repository Compromise
Reported 27 Apr 2026 by otx · Severity: medium
Xinference, an open-source distributed AI model inference framework, suffered a supply chain attack when attackers compromised PyPI release credentials of maintainers and published three malicious versions (2.6.0, 2.6.1, 2.6.2) on April 22, 2026. The malicious code, encoded in Ba