JarkaStealer is a malware variant delivered via malicious PyPI packages that imitated LLM-related libraries. The packages provided some partial legitimate functionality, such as scraping LLM responses through proxy interfaces, to reduce the likelihood of user removal while also downloading and installing JarkaStealer on victim systems. Reported capabilities include browser credential theft, exfiltration of session tokens from Telegram, Discord, and Steam, capture of system screenshots, and comprehensive system profiling. The available content specifically associates it with malicious packages masquerading as LLM libraries in the Python package ecosystem. No additional high-confidence details on threat actor attribution, persistence, or infrastructure are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The TeamPCP threat group executed a cascading supply chain campaign in March 2026 that compromised the Trivy security scanner, two Checkmarx IDE extensions, the litellm PyPI package (~97 million monthly downloads), and the telnyx SDK within an eight-day window.
JarkaStealer malware variant, which performed browser credential theft, session token exfiltration from Telegram, Discord, and Steam, system screenshots, and comprehensive system profiling.
Both packages... simultaneously delivering the JarkaStealer malware variant, which performed browser credential theft, session token exfiltration from Telegram, Discord, and Steam, system screenshots, and comprehensive system profiling.
The multi-stage collection pipeline gathered LLM provider API keys... cloud platform credentials for AWS, GCP, and Azure, Kubernetes service account tokens, Docker configurations, CI/CD pipeline secrets, shell history, SSH keys, database credentials, and cryptocurrency wallet files.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware variant that steals browser credentials, exfiltrates session tokens from Telegram, Discord, and Steam, captures screenshots, and profiles infected systems.
Information-stealing malware delivered via malicious PyPI packages masquerading as LLM-related libraries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.