Supply-chain threat intelligence
Risk score
92
Indexed incident for zamino (pypi).
Clones of libraries to access Aminoapps (e.g. legitimate package amino.fix) with added exfiltration of the given credentials
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-06-sorex
Reasons (based on the campaign):
exfiltration-credentials
action-hidden-in-lib-usage
clones-real-package
Indicators
Timeline