A poisoned version of the mrmustard Python library from Xanadu was used to run an information stealer that harvests SSH private keys, AWS credentials, and Kubernetes configurations, exfiltrating them to an attacker server. The malware had multiple persistence mechanisms and targeted research and HPC environments.