Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in ziugxfbvo (PyPI)

ziugxfbvo

Risk score

92

AI summary

Indexed incident for ziugxfbvo (pypi).

Description

During import, the package automatically downloads and executes code that first acts as an infostealer and then starts code acting as a RAT. It connects with a hardcoded C2 server and waits for commands, supporting e.g. executing remote commands, exfiltrating files, recording the screen, executing GUI actions through PyAutoGUI.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-process-support

Reasons (based on the campaign):

  • exfiltration-generic

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

  • rat

  • spyware-like

  • infostealer

  • persistence

  • exfiltration-browser-data

  • exfiltration-crypto

  • files-exfiltration


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents