Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in zamino (PyPI)

zamino

Risk score

92

AI summary

Indexed incident for zamino (pypi).

Description

Clones of libraries to access Aminoapps (e.g. legitimate package amino.fix) with added exfiltration of the given credentials


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-06-sorex

Reasons (based on the campaign):

  • exfiltration-credentials

  • action-hidden-in-lib-usage

  • clones-real-package


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents