Tencent Cloud Issues Xinference Supply Chain Poisoning Risk Alert
2026-04-23 00:26
Odaily News Tencent Cloud announced that its security center has detected a disclosed supply chain poisoning risk in Xinference. This vulnerability could allow attackers to steal highly sensitive information such as cloud credentials, API keys, SSH keys, encrypted wallets, database credentials, and environment variables when users install or import affected versions of the package, and send this information to a remote command and control (C2) server. (Jin10)
