Supply-chain threat intelligence
Risk score
92
Indexed incident for zenomenallib (pypi).
Package is prepared to exfiltrate sensitive files. Different packages use different places for the malicious code: it runs during importing the module, is placed in a native binary, or in the setup.py script
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-08-xenlib
Reasons (based on the campaign):
Indicators
Timeline