TeamPCP strikes again: Xinference (v2.6.0-2.6.2) PyPI package compromised
research.jfrog.comI editorialized the title to include the version range of compromised packages for visibility.
Also, worth mentioning that TeamPCP denies involvement, and instead points to a copycat using their name: https://xcancel.com/tradelots/status/2046928328066543832