Malicious sympy-dev Package Targets SymPy Users with Cryptomining Malware

Malicious sympy-dev Package Targets SymPy Users with Cryptomining Malware

First seen 22 Jan 2026, 21:42 UTC GbhackersThehackernewsCybersecuritynewsScworld 33.6

Article Content

Browse articles
ThreatCluster

A malicious package named sympy-dev has been identified on the Python Package Index (PyPI), impersonating the popular SymPy library. This package employs typosquatting techniques to deliver cryptomining malware, affecting millions of users who download the legitimate SymPy library, which sees tens of millions of downloads monthly.

Timeline

Date unknown
Malicious sympy-dev package discovered on PyPI
Recent
Malicious package delivers cryptomining malware
Date unknown
SymPy community alerted about the impersonation