Supply-chain threat intelligence
zakuraweb
Risk score
92
Indexed incident for zakuraweb (pypi).
Importing the module starts exfiltrating Discord tokens
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-11-morosint
Reasons (based on the campaign):
exfiltration-browser-data
exfiltration-credentials
Credit: OpenSSF (source)
Indicators
Timeline