Skip to content
Malicious sympy-dev Package Targets SymPy Users with Cryptomining Malware

Malicious sympy-dev Package Targets SymPy Users with Cryptomining Malware

First seen 22 Jan 2026, 21:42 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A malicious package named sympy-dev has been identified on the Python Package Index (PyPI), impersonating the popular SymPy library. This package employs typosquatting techniques to deliver cryptomining malware, affecting millions of users who download the legitimate SymPy library, which sees tens of millions of downloads monthly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

Date unknown
Malicious sympy-dev package discovered on PyPI
Recent
Malicious package delivers cryptomining malware
Date unknown
SymPy community alerted about the impersonation

More articles in this cluster (4)

Following this threat?

Track XMRig in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed